1/18
These flashcards cover important vocabulary and concepts related to computer forensics and data acquisition methods.
Name | Mastery | Learn | Test | Matching | Spaced |
|---|
No study sessions yet.
Raw Format
A data acquisition format that creates a bit-by-bit copy of the original data, requiring as much storage as the original disk.
Proprietary Formats
Specialized formats used by forensics tools that may limit the sharing of acquired data between different tools.
Advanced Forensics Format (AFF)
An open-source format developed for capturing forensics images without size restrictions, allowing metadata integration.
Static Acquisitions
Data captures performed on powered-off devices.
Live Acquisitions
Data captures performed on devices that are powered on, often to collect volatile data.
Disk-to-Image File
A method of creating a complete image copy of a disk for forensic analysis.
Logical Acquisition
The process of acquiring only specific files or file fragments of interest instead of the entire disk.
Contingency Planning
Preparation for potential issues in data acquisition, including the need for multiple copies and protection against encryption.
Write Blocking
A hardware or software technique that prevents alteration of data on the source device during forensic acquisition.
RAID (Redundant Array of Independent Disks)
A storage system that combines multiple physical disks into a single logical unit for redundancy and performance.
Remote Acquisition Tools
Software that allows forensic examiners to gather evidence from a suspect’s computer over a network.
Validation Techniques
Methods used to verify the integrity of acquired data, often through hashing algorithms like MD5 and SHA.
dffldd
An enhanced command for data imaging in Linux that includes additional functions beyond the standard dd command.
Write Blocker
A device used to prevent writing to a storage device during forensic analysis to protect the integrity of data.
AccessData FTK
A software suite used for forensic analysis and data acquisition, including creating disk image copies.
ImageUSB
A PassMark Software tool for creating bootable flash drives from disk images.
ASR Data SMART
A forensics analysis tool that can make image files of suspect drives and manage bad sectors.
ProDiscover
A remote acquisition tool utilized to capture system state information and analyze processes.
SIFT
A Linux distribution used for digital forensics, containing various tools and utilities for evidence acquisition.