Dear Donuts you opened a door on a wide world.
I think that creating a forensic distro requires a filosophy that is not the same of a pentest distro.
I do computer forensic all days and also if I think Backtrack is the best Linux distro I've ever seen and also if his field of application is very wide, it lacks very much to be considered a good forensic tool like Helix, Deft etc...
The solution you provide is good but having all disks unmounted by default is boring and I think that modify all this (and the changes that WILL be necessary in the future to remain forensically sound) can go against the "pentest" filosophy and be unuseful for pentest activities.
This because the forensic modifications are always radical and deep, many times involving the kernel and producing sistem-wide side effects.
This is my opinion but maybe a developer can say something more right.



