<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Exploring Digital Forensics Tools in Cyborg Hawk Linux</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Taras Shevchenko National University of Kyiv</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>118</fpage>
      <lpage>124</lpage>
      <abstract>
        <p>s Computer forensics (software and technical expertise) belongs to the category of engineering and technical expertise. It is an important element in a number of computer expertises, because it allows to build a holistic system of evidence comprehensively. The importance of computer forensics is explained by the increased role of the computers in the modern world. A huge number of offenses and crimes is committed precisely with the help of computer technologies. The computer forensics and expertise of computer equipment is especially relevant in criminal and civil cases. Expertise of computers, hardware, software, databases due to the continuous improvement of computer equipment and software is one of the most complex types of research. The community of free software developers is constantly creating assemblies of utilities designed for software and technical expertise. The most popular is the KaliLinux collection, whereas Cyborg Hawk Linux is undeservedly ignored.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>Development of information technologies, penetration of computer technology advancements into applied and
scientific sphere and into everyday human life has its drawbacks, unfortunately. There are many intruders who use these
achievements for mercenary, criminal purposes. In this regard, there is a need to transform special knowledge from the
field of computer information into the field of forensic science to uncover and investigate crimes that relate to computer
technologies. Computer forensic allows obtaining the most reliable information concerning computer crimes. This type
of research is widely used in consideration of cases in civil and criminal legal proceedings and is one of the most
relevant and demanded.</p>
      <p>
        Computer forensics covers a broad range of activities associated with identifying, extracting, and considering
evidences from digital media. It can be defined as the use of scientifically derived and proven methods toward the
preservation, collection, validation, identification, analysis, interpretation, documentation, and presentation of digital
evidence [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] derived from volatile and non-volatile media storage [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Various hardware, software, and information
objects are objects of computer forensics.
      </p>
      <p>Computer forensics can be divided into the following types: hardware, software, network, and information
forensics. The following methods are used in the process of computer forensics:
 method of software research;
 method of hardware research;
 method of information research.</p>
      <p>Carrying out of software and technical expertise is necessary in cases when a crime or an offense was
implemented with using computer facilities or information data, and when special knowledge in the field of computer
technology is required to establish traces of crime and other forensically significant information. In particular, software
and technical expertise provides the solution of the following expert tasks:
 identification of properties, qualities, status and features of the using of technical computer systems;
 establishing the development and using features of software products;
 establishing the facts of the equipment use during the documents creating or committing other actions
related to the crime;
 access to information on attached devices;
 research information created by a user or a program for the implementation of information processes;
 establishing the features of the functioning of the computer facilities which implement network information
technology.</p>
      <p>
        Computer forensics is used to find out the digital evidence using different tools. It is quite difficult and
complex process. Digital investigations take place in three main phases. In first phase, the investigator takes images of
digital device and copies these images from the target device to some other device for in-depth analysis. In second
phase, which is called analysis, the investigator identifies the digital evidence using different types of techniques such
as recovering the deleted files, obtaining information of user accounts, identifying information about the attached
devices like USB, CD/DVD drives, external hard disks and so on. The third phase is called reporting in which the
investigator reconstructs the actual scenario based on the sequence of activities happened on the target system [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        Digital forensic analysis is divided into two main categories. The first category is the static forensic analysis.
During this analysis, all the target devices that are required in the analysis are shutdown. The second category is live
analysis. During this type of analysis, the system stays in the boot mode [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] to acquire pertinent information from the
physical memory content.
      </p>
      <p>
        Live analysis aims at gathering evidence from systems using different operations and techniques related to
primary memory content. Live forensic is the most challenging kind of digital forensic investigations. To perform the
live forensics, it is vital to understand the basic techniques and tools used in digital forensics. The investigator needs to
acquire the complete image of a computer usage history as well as the current state through live forensic analysis tools.
Though static analysis is kind of a developed part of digital forensics, but other techniques related to live analysis need
to be developed to mitigate its weaknesses [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        Classifications of computer forensics tools include open source, proprietary, hardware, software, special
purpose and general purpose [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Each tool has its own advantages and disadvantages. The choice of forensics tools
depends on the nature of the studying, the obtained results, the requirements for safety and economic efficiency of the
tool.
      </p>
      <p>
        Brian Career [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] reports that open source tools are as effective and reliable as proprietary tools. Manson and his
team [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] compared one open source tool and two commercial tools. They found that all three tools produced the same
results with different degree of difficulty.
      </p>
    </sec>
    <sec id="sec-2">
      <title>2 Description of the most popular tools designed for carrying out software and technical expertise</title>
      <p>
        The community of free software developers is constantly creating assemblies of utilities designed for software
and technical expertise. A comprehensive review of the top twenty open source free computer forensics investigation
tools can be found in [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. For a list of proprietary computer forensics tools see [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] and [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>The most popular assemblies of utilities intended for carrying out software and technical expertise are:
- Kali Linux [11] – Kali Linux is an open source project that is maintained and funded by Offensive Security,
a provider of world-class information security training and penetration testing services.
- CAINE [12] (Computer Aided Investigative Environment) – CAINE is the Linux distro created for digital
forensics. It offers an environment to integrate existing software tools as software modules in a user friendly
manner. This tool is open source.
- DEFT [13] (Digital Evidence &amp; Forensic Toolkit) – The Linux distribution DEFT is made up of a GNU /
Linux and DART (Digital Advanced Response Toolkit), suite dedicated to digital forensics and intelligence
activities.
- PHLAK [14] (Professional Hacker’s Linux Assault Kit) – PHLAK is a modular LiveCD Linux distribution
with a focus on pen-testing, forensics, and network analysis. It includes two lightweight GUIs (XFCE4 and
Fluxbox) and loads of tools, including crackers, sniffers, MITM utilities, and data recovery and duplication
utilities.
- Cyborg Hawk Linux [15] – Cyborg Hawk Linux is a Ubuntu based Linux Hacking Distro also known as a
Pentesting Linux Distro it is developed and designed for ethical hackers and penetration testers. Cyborg Hawk
Distro can be used for network security and assessment and also for digital forensics. It also has various tools
suited to the testing of Mobile Security and Wireless infrastructure.
- BackTrack 5 R3[16]–BackTrack is intended for all audiences from the most savvy security professionals to
early newcomers to the information security field. BackTrack promotes a quick and easy way to find and
update the largest database of security tools collection to-date.
- Parrot Security OS [17] – Parrot Security OS is a cloud friendly operating system designed for Pentesting,
Computer Forensic, Reverse engineering, Hacking, Cloud pentesting, privacy/anonimity and cryptography.
Based on Debian and developed by Frozenbox network.
- BackBox Linux[18]–BackBox is a Linux distribution based on Ubuntu. It has been developed to perform
penetration tests and security assessments. Designed to be fast, easy to use and provide a minimal yet complete
desktop environment, thanks to its own software repositories, always being updated to the latest stable version
of the most used and best known ethical hacking tools.</p>
      <p>The using of assembly, rather than individual software tools, can improve reliability, safety and performance.</p>
      <p>The most popular compilation is the KaliLinux, which contains about 300 utilities, whereas Cyborg Hawk
Linux [15], which contains more than 800 tools, is undeservedly ignored.</p>
      <p>The purpose of our research is to describe the capabilities of the Cyborg Hawk Linux tools.</p>
    </sec>
    <sec id="sec-3">
      <title>3 Our Virtual Machine Platform</title>
      <p>Cyborg Hawk is a Linux based operating system that comes with a rich repository of security and forensics
tools. The computer forensics tools are grouped into several categories. We use the forensics tools within the Cyborg
Hawk.</p>
      <p>VMware Workstation is a hypervisor that runs on 64-bit computers [19]. It enables us to set up multiple virtual
machines and network them together. Each virtual machine can execute on different distribution of Linux operating
system. VMware Workstation is proprietary software but we used the trail version for free. Below are the steps for
setting up the platform for our experiment.</p>
      <p>1. Install VMware Workstation on a machine;
2. Create a virtual machine on the VMware workstation;
3. Install Cyborg Hawk Linux on the virtual machine;
4. Launch Cyborg Hawk Linux from the virtual machine;
5. From the list, select forensics and then select a tool.</p>
    </sec>
    <sec id="sec-4">
      <title>4 Description of the Cyborg Hawk Linux tools</title>
      <p>The Cyborg Hawk Linux disk image was investigated on a VMware Workstation virtual machine running on a
64-bit computer.</p>
      <p>There are 15 classes in the Cyborg Hawk Linux software analysis toolkit, each of which is divided into
categories and subcategories that contain different number of utilities (table 1).</p>
      <p>Several utilities have been selected in each category. For each of them we investigated its purpose, sequence
and results of work on our virtual machine. One of the conclusions of the studying is that many utilities perform several
functions and thus they belong to different classes and categories in the collection. Therefore, the number of original
programs is much smaller than were stated by the developers of the assembly. In addition, a significant limitation in
using of the assembly is that it is only designed to work with 64-bit processors.</p>
    </sec>
    <sec id="sec-5">
      <title>5 Forensics Tools Experiment</title>
      <p>There are several categories of computer forensic tools in the disk image of Cyborg Hawk Linux v1. Some
categories have several tools. In the following subsections we will study the tools for Forensics.</p>
    </sec>
    <sec id="sec-6">
      <title>5.1 Acquisition</title>
      <sec id="sec-6-1">
        <title>Twenty one tools of this category are divided into 10 groups.</title>
        <p>Let's consider the basic packages of tools.</p>
        <p>AFF Package (affcat, affconvert) orthe Advanced Forensics Format (AFF).AFF was created as an open and
extensible file format for storing disk images and associated metadata. The goal was to create a disk imaging format
that would not block users into their proprietary format, which can limit its analysis. The open standard allows
researchers use their preferred tools for solving crimes, collecting information and resolving security incidents quickly
and efficiently. The format was implemented in AFFLIB which was distributed with an open source license.</p>
        <p>Img package(img_cat, img_stat) outputs the contents of an image file. Image files that are not raw will have
embedded data and metadata. Img_cat will output only the data. This allows you to convert an embedded format to raw
or to calculate the MD5 hash of the data by piping the output to the appropriate tool.</p>
        <p>Img package displays the contents of the image file. Image files that are not raw will have built-in data and
metadata. Img_cat will return only data. This allows converting the built-in format to raw or calculating the MD5 hash
of the data by submitting the output to the appropriate tool.</p>
        <p>TSK KIT(tsk_comparedir, tsk_gettimes, tsk_loaddb, tsk_recover)– compare the contents of a directory with the
contents of an image or local device.Sleuth Kit (TSK) allows exploring the compromised file system of a computer.
TSK is a collection of UNIX command-line tools that can analyze NTFS, FAT, FFS, EXT2FS, and EXT3FS file
systems. TASK reads and processes the file system structures independently, so the file system of the operating system
does not need support.</p>
        <p>There are 4 tools in this category (Luks-Ops, TrueCrack, TrueCrypt, Tcpcryptd).</p>
        <p>TrueCrypt is a program for installing and maintaining a drive immediately. Immediate encryption means that
the data is automatically encrypted or decrypted immediately before downloading or saving it without user intervention.
Any data stored on the encrypted volume can be read (decrypted) without using the correct password or the correct
encryption key. The TrueCrypt volume before decryption is nothing more than a series of random numbers.</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>5.2 Cryptography</title>
    </sec>
    <sec id="sec-8">
      <title>5.3 Data recovery</title>
      <p>The tools of this category are divided into four groups (Carving Tools, Password Forensics, PDF Forensics,
Ram Forensics).</p>
      <p>Carving Tools contains 20 programs that specialize in recovering files, missing disk partitions, etc.</p>
      <p>Password Forensics contains 3 programs (chntpw, md5deep, rahash2), which allow to delete passwords to
Windows, calculate and compare MD5 hash-functions and checksums. The main set of tools for password security is in
the category of the fourth class (table 1).
2.Vulnerability assessment
3. Exploitation Toolkit
4. Privelege Escalation
5. Maintaining Access
6. Reporting
7. Reverse engineering
8. Stress tests
9. Forensics
10. Wireless Toolkit
11. RFID / NFC tools
12. Hardware Hacking
13. VOIP Analysis
14. Mobile Security
15. Malware Analysis</p>
    </sec>
    <sec id="sec-9">
      <title>5.4 Digital anti-forensics</title>
      <p>Chkrootkit is the only tool in this category. Chkrootkit is a scanner that monitors the presence of rootkits on
the local system by some search attributes. The program has several modules to search for rootkits and other unsafe
objects. As expected, rootkits in our virtual machine were not detected.</p>
      <p>There are14 tools in this category (autopsy, binwalk, bulk_extractor, chkrootkit, dc3dd, dcfldd, extundelete,
foremost, fsstat, galleta, tsk_comparedir, tsk_gettimes, tsk_loaddb, tsk_recover).</p>
    </sec>
    <sec id="sec-10">
      <title>5.5 Digital forensics</title>
    </sec>
    <sec id="sec-11">
      <title>5.6 Forensics evaluation tools</title>
      <p>There are40 tools in this category (affcompare, affcopy, affcrypto, affdiskprint, affinfo, affsign, affstats, affuse,
affverify, affxml, autopsy, binwalk, blkcalc, blkcat, blkstat, bulk_extractor, cuckoo, ffind, fls, foremost, galleta, hfind,
icat-sleuthkit, ifind, ils-sleuthkit, istat, jcat, mactime-sleuthkit, missidentify, mmcat, pdgmail, readpst, reglookup,
reglookup-timeline, reglookup-recover, SIGFIND, sorter, srch-strings, tsk_recover, vinetto).</p>
      <p>AFF Packagewas considered in 5.1.</p>
      <p>Libewf package(ewfacquire, ewfacquirestream, ewfexport, ewfinfo, ewfverify)writes data of data carriers from
devices and files into EWF files.Ewfacquire can be used to create disk images in the EWF format. It includes several
message digests including MD5 and SHA1. To create an image of /dev/sdb1 and logging data to /root/Desktop/log.txt,
we obtained the image by issuing this command on CyborgLinuxewfacquire -d sha1 -l /root/Desktop/log.txt /dev/sdb1.</p>
    </sec>
    <sec id="sec-12">
      <title>5.7 Forensics suite</title>
      <p>There are 5 tools in this category (autopsy, capstone, dff, dff-gui, dumpzilla). DFF (Digital Forensics
Framework) is used to collect, preserve and identify digital evidence. We need to load pre-prepared file with a forensic
image into DFF and analyze the data file by one of the built-in modules (figure 1).</p>
    </sec>
    <sec id="sec-13">
      <title>5.8 Network investigation</title>
      <sec id="sec-13-1">
        <title>There are 2 tools in this category (p0f, xplico).</title>
        <p>P0f is a passive operating systems fingerprinting tool. All the host has to do is connect to the same network or
be contacted by another host on the network. The packets generated through these transactions gives p0f enough data to
guess the system. In our experiment, by issuing the command p0f -f /etc/p0f -i eth0, we were able to read fingerprints
from /etc/p0f and listen on eth0 via libpcap application.</p>
        <p>Xplico is a Network Forensic Analysis Tool (NFAT) that is capable of extracting application data from packet
capture files. It is best suited for offline analysis of PCAP files but it can also analyze live traffic. Xplico can extract
email, HTTP, VoIP, FTP, and other data directly from the PCAP files. It is able to recognize the protocols with a
technique named Port Independent Protocol Identification (PIPI).</p>
      </sec>
    </sec>
    <sec id="sec-14">
      <title>5.9 Secure wipe</title>
      <sec id="sec-14-1">
        <title>The tools in this category include 4 tools (sdmem, sfill, srm, sswap).</title>
      </sec>
    </sec>
    <sec id="sec-15">
      <title>5.10 Steganography</title>
      <sec id="sec-15-1">
        <title>8 tools of this category are divided into 2 groups.</title>
        <p>Steg Toolkit(stegbreak, stegcompare, stegdetect, stegdeimage, steghide) isused for the embedding system and
the password when the attack succeeded for an image.</p>
        <p>Snowdrop is intended to bring (relatively) invisible and modification-proof watermarking to a new realm of
“source material” – written word and computer source codes. The information is not being embedded in the least
significant portions of some binary output, as it would be with a traditional low-level steganography, but into the source
itself.</p>
        <p>Vinetto extracts the thumbnails and associated metadata from the Thumbs.db files.</p>
        <p>Outguess is a universal steganographic tool that allows the insertion of hidden information into the redundant
bits of data sources. The nature of the data source is irrelevant to the core of outguess. The program relies on data
specific handlers that will extract redundant bits and write them back after modification. Currently only the PPM, PNM,
and JPEG image formats are supported, although outguess could use any kind of data, as long as a handler were
provided.</p>
        <p>Stegdetectwill look for signatures of several well-known steganography embedding programs in order to alert
the user that text may be embedded in the image file, such as jpeg. To see if there is steganography embedded message
in our n.jpg file in a USB drive, we launched Stegdetectby using this command:stegdetect -t
/media/cyborg/B4FE5315/n.jpg.</p>
        <p>The result of executing the utility is shown below:stegdetect -t /media/cyborg/B4FE-5315/n.jpg: negative,
wherenegative indicates no message embedded in the n.jpg file.</p>
        <p>In this paper we have demonstrated the application of various computer forensics tools on Cyborg Hawk
Linux. We showed the syntax for using the tools and the result of executing the tools on our virtual machine. As it was
demonstrated the tools produce consistent results according to their specifications. However, similar results can be
obtained by using physical machines. Our results will help the computer forensics investigators on selecting appropriate
tool for a specific purpose. It also helps penetration testers to check for signs of vulnerabilities on their system. We
showed that Cyborg Hawk Linux is a good choice for forensics investigators for several reasons. These include that the
tools are free, easy to use, do not need configuration, and produce consistent results.</p>
      </sec>
    </sec>
    <sec id="sec-16">
      <title>5 Conclusions</title>
      <p>11. KaliLinux[Online]. Available: https://www.kali.org/[Accessed Oct. 27, 2017]
12. CAINE (Computer Aided INvestigative Environment) [Online]. Available: http://www.caine-live.net/[Accessed Oct.</p>
      <p>27, 2017]
13. DEFT (Digital Evidence &amp; Forensics Toolkit) [Online]. Available:http://www.deftlinux.net/[Accessed Oct. 27,
2017]
14. PHLAK [Online]. Available:https://sourceforge.net/projects/phlakproject/[Accessed Oct. 27, 2017]
15. Cyborg Hawk Linux [Online]. Available:http://cyborg.ztrela.com/[Accessed Oct. 27, 2017]
16. BackTrack[Online]. Available:http://www.backtrack-linux.org/[Accessed Oct. 27, 2017]
17. Parrot Security OS [Online]. Available:https://www.parrotsec.org/[Accessed Oct. 27, 2017]
18. BackBox Linux [Online]. Available:https://backbox.org/[Accessed Oct. 27, 2017]
19. VMware [Online]. Available: http://www.vmware.com[Accessed Oct. 27, 2017]</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>O.L.</given-names>
            <surname>Carroll</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.K.</given-names>
            <surname>Brannon</surname>
          </string-name>
          , and T. Song, “
          <article-title>Computer forensics: Digital forensic analysis methodology”</article-title>
          ,
          <source>Comp. Forensic</source>
          , vol.
          <volume>56</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          , Jan.
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>M.</given-names>
            <surname>Meyers</surname>
          </string-name>
          and
          <string-name>
            <given-names>M.</given-names>
            <surname>Rogers</surname>
          </string-name>
          , “
          <article-title>Computer forensics: The need for standardization and certification”</article-title>
          ,
          <source>Int. J. Digit. Evidence</source>
          , vol.
          <volume>3</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>11</lpage>
          , Sep.
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <given-names>S.</given-names>
            <surname>Rahman</surname>
          </string-name>
          and
          <string-name>
            <given-names>M. N. A.</given-names>
            <surname>Khan</surname>
          </string-name>
          , “
          <article-title>Review of live forensic analysis techniques”</article-title>
          ,
          <source>Int. J. of Hybrid Inf. Technology</source>
          ,vol.
          <volume>8</volume>
          , no.
          <issue>2</issue>
          , pp.
          <fpage>379</fpage>
          -
          <lpage>388</lpage>
          ,
          <year>2015</year>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>S.</given-names>
            <surname>Yadav</surname>
          </string-name>
          , “
          <article-title>Analysis of digital forensic and investigation”</article-title>
          ,
          <source>VSRD-IJCSIT</source>
          , vol.
          <volume>1</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>171</fpage>
          -
          <lpage>178</lpage>
          ,
          <year>2011</year>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>A.</given-names>
            <surname>Ghafarian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Seno</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Amin</surname>
          </string-name>
          . “
          <article-title>Exploring digital forensics tools in Backtrack 5.0 r3”</article-title>
          .
          <source>Proceedings of International Conference on Security and Management - SAM'14</source>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>B.</given-names>
            <surname>Carrier</surname>
          </string-name>
          “
          <article-title>Open source digital forensics tools: The legal argument”</article-title>
          .
          <source>AtStake</source>
          . Oct.
          <year>2002</year>
          . [Online]. Available: http://dl.packetstormsecurity.net/papers/IDS/atstake_opensource_forensics.pdf[Accessed Oct.
          <volume>27</volume>
          ,
          <year>2017</year>
          ]
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>D.</given-names>
            <surname>Manson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Carlin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Ramos</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gyger</surname>
          </string-name>
          , M. Kaufman, and
          <string-name>
            <given-names>J.</given-names>
            <surname>Treichelt</surname>
          </string-name>
          . “
          <article-title>Is the open way a better way? Digital forensics using open source tools”</article-title>
          .
          <source>System Sciences. HICSS</source>
          <year>2007</year>
          . 40th Annual Hawaii International Conference on Science, pp
          <fpage>266</fpage>
          -
          <lpage>270</lpage>
          . [Online]. Available: https://www.computer.org/csdl/proceedings/hicss/2007/2755/00/27550266b.pdf[Accessed Oct.
          <volume>27</volume>
          ,
          <year>2017</year>
          ]
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <given-names>A.Z.</given-names>
            <surname>Tabona</surname>
          </string-name>
          “
          <article-title>Top 20 free digital forensics investigation tools for sysadmins”</article-title>
          .[Online].
          <year>2002</year>
          .Available :http://www.gfi.com/blog/top-20
          <string-name>
            <surname>-</surname>
          </string-name>
          free
          <article-title>-digital-forensic-investigation-tools-for-sysadmins/</article-title>
          [Accessed Oct.
          <volume>27</volume>
          ,
          <year>2017</year>
          ]
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. Wikipedia, “
          <article-title>List of digital forensics tools”</article-title>
          . [Online]. Available :http://en.wikipedia.org/wiki/List_of_digital_forensics_tools [Accessed Oct.
          <volume>27</volume>
          ,
          <year>2017</year>
          ]
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10. Mares and Company,“
          <article-title>Alphabetical list of links to manufacturers, suppliers</article-title>
          , and products”.[Online]. Available http://www.dmares.com/maresware/linksto_forensic_tools.htm [Accessed Oct.
          <volume>27</volume>
          ,
          <year>2017</year>
          ]
          <fpage>123</fpage>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>