Quote:
Granted, the windows tools have been heavily refined to automate the tasks involved in investigations, but the principal issue I struggle with, is why use a single minded, inferior operating system to do forensics? Why are programs like encase and FTK made only for windows, when the core operating system does nothing but hamper an investigation?
Because Windows is still in widespread use in the corperate network (and the government which is huge cash as well). When people switch over they'll have to switch right? Basic economics ^_^.