PALADIN 32

PALADIN EDGE (32-Bit) is a modified “live” Linux distribution based on Ubuntu that simplifies various forensics tasks in a forensically sound manner via the PALADIN Toolbox. PALADIN EDGE (32-Bit) was designed to be lightweight and support 32-bit systems.

PALADIN EDGE (32-bit) is available for FREE. However, we kindly request a donation to support the project and keep the updates coming. You can make a contribution by modifying the price below. Thank you in advance for your support!

PALADIN 32 is a modified “live” Linux distribution designed specifically to support legacy 32-bit systems while maintaining forensic soundness and ease of use.

At its core is the PALADIN Toolbox, an intuitive GUI that simplifies complex forensic tasks like imaging, cloning, wiping, and searching—no command line required.

PALADIN 32 is available for FREE, but your donation helps us maintain and evolve the tool for agencies and investigators around the world.

PRODUCT DESCRIPTION

PALADIN 32 – Forensic Power in a Lightweight Package

Designed to support older 32-bit hardware, PALADIN 32 offers forensic examiners a flexible, easy-to-use live environment for imaging, triage, analysis, and reporting. Built on Ubuntu Linux and equipped with the powerful PALADIN Toolbox, this tool is a must-have for anyone maintaining legacy systems in their forensic workflow.

PALADIN 32 BIT Interface

PALADIN Toolbox – Simplified Forensic Workflow

The PALADIN Toolbox combines trusted forensic applications into a streamlined interface:

Key Capabilities

  • Boot any compatible 32-bit system into a secure forensic environment
  • Image to multiple formats: .E01, .Ex01, .dmg, .dd, SMART, AFF, VMDK
  • Clone devices or create dual forensic images simultaneously
  • Convert image formats easily with the built-in Image Converter
  • Perform network imaging via NFS or SMB
  • Format media as NTFS, HFS+, FAT32, EXT4, or ExFAT
  • Image only Unallocated, Free Space, or File Slack
  • Wipe drives securely with optional post-wipe verification
  • Auto-generate and export MD5 and SHA1 hashes
  • Search and preview files by name, keyword, or MIME type

Tabs & Tools

  • Imager Tab: Output to one or two destinations simultaneously; supports all major forensic formats
  • Find Tab: Search and preview files with filtering by name, content, or file type
  • Unallocated Tab: Isolate and capture unallocated and slack space as standalone files for carving
  • Disk Manager: Visualize partitions, mount volumes read-only or read/write, and verify integrity
  • Images Tab: Mount and explore image partitions
  • Network Share Tab: Mount network volumes for acquisition or output

Logging Options

  • Task Logs: Record each action during a session
  • Live Logs: Show real-time status of current tasks
  • Choose destination for logs via the Logs menu

Continued Support from the Forensic Community

PALADIN 32 is provided at no cost as a service to digital forensic professionals. Like you, our team includes examiners who understand the challenges of working with limited budgets.

Your donation—of any size—helps us keep PALADIN available and up to date for everyone.

PRODUCT DESCRIPTION

PALADIN EDGE (32-bit) is a modified “live” Linux distribution based on Ubuntu that simplifies various forensics tasks in a forensically sound manner via the PALADIN Toolbox. PALADIN is a complete solution for triage, imaging, examination.

Please Read Carefully: In order to download PALADIN EDGE you must create an account and agree to the Terms and Conditions of using our services and this site. These terms include giving us permission to contact you about SUMURI news, products, updates and events. You may opt-out gracefully at anytime.

paladin_edge.iso: de866310f4ea3e17e5762ad4e605c385

PALADIN 6.08 Changelog:
  • Workaround added for sporadic memory leak in Expert Witness Format imaging and verification.
  • Removed option for segmenting forensic images to prevent issues related to maximum segment limits.
PALADIN TOOLBOX

This is the PALADIN application you have all come to love completely recoded and streamlined. Designed to make you a Forensic Rockstar!

PALADIN Toolbox Key Features
  • Boot your computer into a safe environment
  • Image to several formats including Expert Witness (.E01, .Ex01), Apple Disk Image (.dmg) and Raw (.dd), SMART, AFF and VMDK!
  • Clone devices
  • Create two forensic images or clones at the same time
  • Image across a network
  • Format any drive as NTFS, HFS+, FAT32 or EXT4 and ExFAT
  • Create a forensic image of only the Unallocated Space, Free Space and File Slack
  • Quickly wipe (sterilize), verify and hash media
  • Search and preview media by file name, keywords or MIME types.
Logging

There are two types of logs in PALADIN – Task Logs and Live Logs. Task Logs keep a record of all tasks during a session. Live Logs provide information regarding the current task. You can save you logs to any destination by choosing “Select media to store logs” from the Logs menu.

IMAGER TAB

The Imager Tab allows you to output to two destinations simultaneously. Here you can choose between a .dmg, .dd .E01, .Ex01, SMART, AFF or .vmdk image formats. Selecting “Device” allows you to create a clone. You can also convert one forensic image to another by using the Image Converter Tab.

FIND TAB

File previews anyone? Make sure you have a drive mounted as read/write in order to save results. Select your drive to preview. Search by file name, content (keywords), or MIME/File Signatures (www.webmaster-toolkit.com/mime-types.shtml). Select your destination drive and provided a name for your search. Your files will begin to populate in an Explorer window! Select Copy Original to export your results.

UNALLOCATED TAB

Many file carving utilities exist but how do you grab just the unallocated space, file slack and free space from a drive and save this as a file? The Unallocated Tab is your solution.

DISK MANAGER

Refresh Button – Drive not showing up in the drop-down boxes? Hit the new Refresh Button to tell PALADIN to re-poll the devices!

Mount/UnMount Buttons – These buttons allows you to mount and unmount drives Read-Only or Read-Write. Simply select which volume you would like to mount or unmount from the list and go!

Verify Button – The Verify Button will generate a MD5 and SHA1 hash for any device or forensic image selected.

Format Button – The Format Tab allows you to format a drive with an HFS+, FAT32, ExFAT, NTFS or EXT4 file system.

Wipe Button – Need to sterilize your drive? The Wipe Button will write zeros across the entire drive in a single pass. A new Verify after Wipe feature was added for extra peace of mind!

Images Tab – PALADIN allows you to mount a partition from your forensic image.

Samba/Window Share Tab – PALADIN allows you to add a Network Volume by selecting Mount and adding the appropriate information.

 

PALADIN and PALADIN Toolbox is developed as a courtesy for the forensic community from the SUMURI team. We hope that you put PALADIN to good use. We realize that many agencies have limited or no budgets. We have sat in your seats so we understand. We were and are examiners too.

We hope that you can use PALADIN to make the world a better place.
Scroll to Top