With forensics application in mind, Masterkey has been developed with the following features by default:- Masterkey comes with a collection of forensics tools for imaging, data carving, forensic analysis and network analysis as well as other applications including: editors, office suite, multimedia tools, file and disk management tools, etc.
- Disk partitions found by Masterkey during bootup are not mounted automatically. This prevents a user from accidentally writing to the evidence disks and therefore contaminating the evidence. Icons of these found partitions are linked and displayed on the user's Desktop. By clicking the icon of a disk partition, the disk partition will be mounted as read-only.
- Mounting and use of swap partitions is not allowed. This prevents a user from destroying any evidence present on swap partitions.
- Root privilege. The user works with the system as a super user (administrator) so that tools requiring root privilege can be used straightaway.
- Console login. The Desktop environment (graphic user interface) does not start automatically during bootup. This makes it possible to work with Masterkey on older computers. The user can choose to start either the KDE or Fluxbox desktops if they wish.
|