As Linux kernel-based operating systems gain market share there will be an inevitable increase in Linux systems that law enforcement agents must process at cybercrime scenes. The skills and expertise required to recover evidence from Microsoft Windows-based systems do not necessarily translate to Linux systems. Although the procedures required to identify, recover, and examine evidence on Windows and Linux systems may appear similar at an level, the “devil is in the details” as they say. This paper provides an