TrueBack is a cyber forensics software tool for digital evidence seizure and acquisition.
TrueBack is available on DOS, Windows and Linux and distributed on a Boot Floppy or CD. The investigating officer can boot the suspect’s system from the boot Floppy or CD supplied to him.
Perform Seize, Acquire or do both seize and acquire together with Trueback which is NIST Compliant. Solutions and available for both Windows and Linux Operating system. The tool creates a report on seizure acquisition process which has details of the entire process with hash values, exhibit details and the system details as well.
TrueBack allows investigators to preview the storage media before seizure. It enables investigators to electronically seize or acquire the digital evidence and create the report of the seizure with all details.
TrueBack: Now Available
Developed for Indian Law Enforcement Agencies
Available on DOS, Linux and Windows
NIIST, USA disk imaging tool specification complaint
Uses MD5 Hash for authentication
Preview of suspect media in Windows and Linux versions
Creation of block hashes to prevent loss of evidence
Supports IDE, SCSI, SATA, CD, DVD, Floppy, USB and Firewire devices
Disk Imaging facility with compression for any media
Facility for seizure, Acquisition or Seizure & Acquisition
Local, Parallel Port or Network Acquisition
Acquisition of partition or whole media to Hard disk, USB or Firewire devices.