Paul Drake made a comment post to this blog entry that i felt was worth mentioning here as a new blog entry.
Paul made us aware of another option. This is called Helix. Helix is a customised distribution of Knoppix Live Linux CD. The Helix CD can be booted using customised different versions of the kernel. It is a bootable live CD and includes tools that are dedicated to Incident response and forensics. The CD has been created specifically so that it does not alter the HOST PC in anyway. This CD is used by SANS in the Track 8: System Forensics, investigation and response course.
The above paragraph is paraphrased from the Helix website for this CD. Go there to see their own details, FAQ, contents and download.
Details of the SANS forensics course can be found here.