1/12
How to make a forensic copy without changing the original evidence?
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Forensic Workflow HIgh Level [the process of working w/ evidence from start to finish]
Extract storage media
Acquire forensic copy
Authenticate with hashes
Analyze working copy
Report findings
The 3 A’s of Acquisition
Acquire the evidence • Authenticate the copy • Analyze the data
Types of Acquisition
Static = system is off, Live = system is running
Common Acquisition Methods
Physical : bit stream disk to image, or disk to disk
Logical
What is Bit-stream Disk-to-Image? What are its use cases?
a forensic image file (.E01, .dd) containing a bit-for-bit copy of the source. contains storage at bit level including active, deleted, slack and hidden areas.
Use Case- you need a forensic copy for analysis and long term storage.
What is Bit-stream Disk-to-Disk, what are its use case?
Creates an exact physical clone of the suspect drive onto another drive. (one device into another same device)
Use cases: You need a working duplicate of the drive rather than an image, uncompressed data and can work directly upon being mounted to correct devices
What is a Logical Acquisition? What is its catch? What is its use case?
Copies selected files and folders available through the file system rather than a complete bit-for-bit image.
Fast but limited is its catch.
When only active files and folders are needed, and time/storage is limited
Logical Acquisition vs Physical Acquisition
Logical : active files and folders avail. in file system/
Physical: unallocated space, deleted space remnants, active data.