В приложении к документу " Responding to targeted cyberattacks" (ISACA) представлен полезный перечень ссылок "Investigative Tools". Делюсь:
 
   - 
       SANS SIFT Workstation: Investigative Forensic Toolkit
– Login: sansforensics
 
   – Password: forensics
 
   
 
   - REMnux: A Linux Distribution for Reverse-Engineering Malware
– Operate in REMnux as the user: remnux
 
   – Default password for this account: malware
 
   
 
   - Backtrack: A Linux Security Distribution
– Default user name: root
 
   – Default password: toor