Buscador Investigative Operating System

Buscador is a Linux Virtual Machine that is pre-configured for online investigators. It was developed by David Westcott and Michael Bazzell, and distributions are maintained on this page. The current build is 3GB and includes the following resources (Further Info):

Custom Firefox Install and Add-Ons
Custom Chrome Install and Extensions
Tor Browser
Custom Video Manipulation Utilities
Custom Video Download Utility
Recon-NG
Maltego
Creepy
Metagoofil
MediaInfo
ExifTool
TheHarvester
Wayback Exporter
HTTrack Cloner
Web Snapper
Knock Pages
SubBrute
Twitter Exporter
Tinfoleak
BleachBit
VeraCrypt
KeePass

Installation Notes

You will need a Virtual Machine application in order to use this system. VirtualBox is free and will suffice for most investigations. Some users prefer a more robust option with VMWare Workstation for Windows or VMWare Fusion for Mac. Any of these options will get you started.

VirtualBox Installation and Configuration:

1) In the VirtualBox menu, click on File > Import Appliance
2) Navigate to the OVA file that was downloaded (Buscador)
3) Choose this file and select "Import"
4) Before starting the new machine, highlight it and choose "Settings"
5) Under General > Basic, rename this machine as desired (Buscador?)
6) Under General > Advanced, change Shared Clipboard to Bi-Directional
7) Under System > Motherboard, increase the RAM if you have ample resoucres (half of total system)
8) Under Display > Screen, increase the Video Memory to 128MB is available
9) Under Storage, click the small "plus" in the lower left corner, "Add Optical Drive", and "Leave Empty"
10) Under Shared Folders, click the "plus" on the right, choose folder to store evidence, select "Auto-Mount"
11) Click "OK" and launch the new machine
12) Upon boot, log into the user "osint" with the password of osint
13) In the VirtualBox Menu, select Devices > "Insert Guest Additions CD Image"
14) Allow the image to be installed, and reboot upon completion.
15) Start the Terminal in the new VM and type sudo adduser osint vboxsf
16) Provide the password as needed (osint)
17) Reboot

You should now have access to the shared directory in order to save data to the host operating system (evidence). It can be found in the File Manager (Home), on the left column, titled "sf_" followed by the name of the folder to which it is connected. This shared folder will also be on your desktop for easy access. You can make the machine full-screen, copy and paste text to and from the image, and you are ready to begin using the applications.

VMWare Installation and Configuration:

1) In the VMWare menu, select File > Import > Select OVA
2) Select the location where the VM will be imported. Click "OK" Click "Retry" if the initial import fails
3) Power on the VM and Login to the OS
4) Install VMware tools as appropriate for your version:

VMWare Fusion: In the menu, select Virtual Machine > Install VMware Tools
VMWare Workstation: In the menu, select VM > Install VMware Tools
VMWare Player: In the menu, select Player > Manage > Install VMware Tools. Note:

5) Open (Double Click) the VMware Tools CD mounted on the desktop
6) Right-click the file that is similar to VMware.xx.tar.gz and click Extract to, and select Desktop
7) Open Terminal (Select 'No' to avoid an update) and type cd Desktop/vmware-tools-distrib
8) Type sudo ./vmware-install.pl and enter password (osint).
9) Type Y when prompted about downloading from the Linux repository
10) Accept all default values by striking the enter/return key at every prompt.
11) Reboot the VM
12) Enable Shared Folders from the file menu: Settings > Options > Shared Folders (Always Enabled)
13) Add a Shared Folder by selecting the desired folder on the host OS
14) Create a shortcut to the shared folder on the desktop with the following command in the terminal:
ln -s /mnt/hgfs/foldername /home/osint/Desktop/Shared_Folder

Usage Notes

A great feature of virtual machines is the use of Snapshots. These "frozen" moments in time allow you to revert to an original configuration or preserve an optimal setup. Most users install the virtual machine as detailed above, and then immediately create a snapshot of the unused environment. When your virtual machine eventually becomes contaminated with remnants of other investigations, or you accidentally remove or break a feature, you can sinmply revert to the previously created snapshot and eliminate the need to ever re-install.

VirtualBox use of Snapshots

1) Completely shut down the Virtual Machine
2) In the VirtualBox Menu, click on the Snapshots button in the upper right
3) Click on the blue camera icon to "take a snapshot"
4) Create a name and any notes to remind you of the state of the machine, such as "New Install"
5) Click OK

You can now use your virtual machine as normal. If you ever want to revert to the exact state of the machine that existed at the time of the snapshot, follow these instructions:

1) Completely shut down the Virtual Machine
2) In the VirtualBox Menu, click on the Snapshots button in the upper right
3) Select the desired snapshot to apply
4) Click on the blue camera icon with arrow to "restore snapshot"
5) Click Restore

Optionally, if you ever want to remove a snapshot, simply use the icon with a red X. This will remove data files to eliminate wasted space, but you cannot restore to that image once removed. It will not impact the current machine state. Many users remove old, redundant snapshots after creating newer clean machines.

VMWare Use of Snapshots (VMWare Workstation or Fusion, NOT Player)

1) Completely shut down the Virtual Machine
2) In the VMWare Menu, click on the Snapshots button in the upper right
3) Click on the camera icon to "take" a snapshot
4) Create a name and any notes to remind you of the state of the machine, such as "New Install"
5) Click Take

You can now use your virtual machine as normal. If you ever want to revert to the exact state of the machine that existed at the time of the snapshot, follow these instructions:

1) Completely shut down the Virtual Machine
2) In the VMWare Menu, click on the Snapshots button in the upper right
3) Select the desired snapshot to apply
4) Click on the camera icon with arrow to "restore" a snapshot
5) Click Restore

Optionally, if you ever want to remove a snapshot, simply use the "delete" icon. This will remove data files to eliminate wasted space, but you cannot restore to that image once removed. It will not impact the current machine state. Many users remove old, redundant snapshots after creating newer clean machines.

It is suggested to enable VMware autoprotect snapshots, set to daily, and limit the snapshot count to 3. Autoprotect snapshots are an easy way to always have a snapshot to revert to. The following steps will enable this feature.

1) Select the virtual machine and select VM > Settings
2) On the Options tab, select AutoProtect and select Enable AutoProtect
3) Select the "Daily" interval between snapshots
4) Select the maximum number of AutoProtect snapshots to retain (Recommended "3")
5 Select OK to save your changes

After the maximum number of AutoProtect snapshots is reached, Workstation deletes the oldest AutoProtect snapshot each time a new AutoProtect snapshot is taken. This setting does not affect the number of manual snapshots that you can take and keep.

USB Live Boot

Every online investigation computer should have a selection of removable operating systems ready to boot at any time. While optical media such as compact discs could be used to boot a computer, creating bootable USB devices is the easiest and most robust solution. The general premise of this method is to create a USB drive that can be used to boot an entire operating system from itself. After completing these instructions, you will have a USB drive the size of a quarter that possesses its own operating system, custom browser, investigation extensions, and Android emulator. Insert it into practically any computer and receive a fast and secure solution to online investigations.

Requirements:

A computer capable of booting to USB. This can be Windows or Mac OS X hardware (Macs are preferred), and most computers made in the past 10 years will work. You may need to hold down a specific key on your keyboard while booting to force the machne to boot to the USB drive. On Apple computers, it is the Alt/Option key. On many Windows machines it is a function key such as F2, ESC, or DEL.

A small USB 3.0 drive. I prefer the Sandisk Utra Fit 16GB drive (LINK). You will also need a USB 3.0 port on your computer. Windows ports are often blue in color while Apple ports are not. This WILL work on older ports, but may be too slow to be useful.

A micro USB Wi-Fi adapter (Link). While you may already have native network access, the new operating system may not recognize your drivers. This $10 piece of hardware ensures a working system without configuration.

The Buscador Linux operating system (ISO LINK). User name and password is osint.

Windows Users: A program called Rufus (LINK).

Mac Users: A program called UNetBootin (LINK).

Instructions:

1) Insert your desired USB drive that will be overwritten.
2) Execute the Rufus program and choose your USB drive.
3) Choose a partition scheme of “MBR … for BIOS or UEFI Computers”.
4) Click the button similar to a CD and choose the appropriate ISO file that you downloaded.
5) Click “Start” and allow the process to complete.
6) Reboot the computer and select the USB drive upon boot sequence.



Download OVA

Download: Version 1.0 - Feb 23 2017
Torrent: Soon

Checksums:

SHA-256:
e6c9398d8635451c362733e6d6561ec8
ff3660202463edbe41d262f49d1d619d

SHA-1:
8ffcb1678a5399e1687e9947ffb3baaf99f
92ae7

What is a Checksum?

Download ISO

Download: Version 1.0 - Feb 23 2017
Torrent: Soon

Checksums:

SHA-256:
0ebf716f90cd1b532ca86fd06b3be963b5
0abb87b867e442036467fa857e336c

SHA-1:
fd04943a14977480f767a4a3955412ae7f
d5b47c

What is a Checksum?

Video Training

You can order our online OSINT video training package with any credit card right now and receive immediate access to the entire training! Click below to order today.

 

Contact Us to order by check or money order.

New OSINT Guide

The Fifth Edition of my book on internet search techniques is now available. Click the book below for details.

Support & Updates

While we do not offer technical support for Buscador, the IntelTechniques forums has a dedicated discussion group about usage of the system. Please post any questions there. All updates since the latest release will be posted below and instructions will be explained in the forum.

FFMPEG - Script Fix

Additionally, the following specific manuals may be helpful.

Recon-ng Guide

Maltego Guide I

Maltego Guide II

If you would like further instruction, the IntelTechniques Video Training Course has a dedicated section that will focus exclusively on the setup and usage of Buscador.