Trusted Response Kit
Definition
A portable collection of statically compiled, cryptographically verified forensic tools stored on write-protected media. Used during live response to avoid executing potentially compromised system binaries on the suspect host.
- Contents
- Statically compiled, cryptographically verified forensic tools
- Storage
- Write-protected media
- Purpose
- Avoid executing potentially compromised system binaries
- Use phase
- Live response, live state capture
Common questions
Why does the kit favor statically compiled tools rather than tools that call system libraries?+
A compromised host can have its shared libraries hooked or replaced by malware to hide processes or files, so a dynamically linked tool run on that host could return falsified results. Static compilation avoids depending on the potentially tampered libraries.
Why is cryptographic verification of the kit's tools important?+
It confirms the binaries have not been altered since they were built, which matters for evidentiary integrity and for ruling out the possibility that the response toolkit itself was tampered with before use.
Related terms
- ARP Cache
- A table held in memory that maps IP addresses to hardware (MAC) addresses for recently contacted hosts on the local network. ARP...
- DNS Resolver Cache
- A temporary store of DNS query results held by the operating system. Entries reveal which domain names a host has recently resolved,...
- Live Response
- The process of collecting evidence and triage data from a running system without first powering it down. Preserves volatile artefacts that would...
- Order of Volatility
- The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
- Process Tree
- A structured representation of running processes showing each process alongside its parent. Malware frequently spawns command shells or other processes from unexpected...