# Forensic Soundness of Live Linux Distributions

**URL:** <https://community.metaspike.com/t/forensic-soundness-of-live-linux-distributions/276>\
**Category:** Digital Forensics\
**Created:** [March 6, 2020, 5:51pm UTC](https://community.metaspike.com/t/forensic-soundness-of-live-linux-distributions/276 "2020-03-06T17:51:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![caseyl4n6](https://community-cdn.metaspike.com/user_avatar/community.metaspike.com/caseyl4n6/32/330_2.png) [@caseyl4n6](https://community.metaspike.com/u/caseyl4n6)\
**Post date:** [March 6, 2020, 5:51pm UTC](https://community.metaspike.com/t/forensic-soundness-of-live-linux-distributions/276/1 "2020-03-06T17:51:42Z")

</div>

Hello,

One of my colleagues brought up this article recently: [A live forensic distribution writing to a suspect drive – My DFIR Blog](https://dfir.ru/2018/07/25/a-live-forensic-distribution-writing-to-a-suspect-drive/)

According to the author’s findings, even some live linux distributions that are labeled “forensic” were altering the data on the suspect drive in some cases. Has anyone compiled a list of:

- Which linux distributions (and possibly winfe) handle this properly
- Any hardware devices such as Ditto, TX1, Falcon etc. that are known to suffer from the same issue?

I found a thread on FF from 2018 where the author of the article says:

> Tableau TX1 is using my kernel patch (but not the userspace tools).

We will do our own testing with the devices that are available to us but just wanted to see if there are any existing test results out there that cover this scenario. Thx

---

<div class="post-metadata">

**Author:** ![agungor](https://community-cdn.metaspike.com/user_avatar/community.metaspike.com/agungor/32/719_2.png) [@agungor](https://community.metaspike.com/u/agungor)\
**Post date:** [March 11, 2020, 9:57pm UTC](https://community.metaspike.com/t/forensic-soundness-of-live-linux-distributions/276/2 "2020-03-11T21:57:35Z")

</div>

The distinction between a hardware and a software write blocker becomes a bit fuzzy when hardware forensic duplicators are built on a custom Linux kernel 😄
