Guide To Computer Forensics: 6 Edition
Guide To Computer Forensics: 6 Edition
Guide To Computer Forensics: 6 Edition
6TH EDITION
CHAPTER 3
DATA ACQUISITION
VALIDATING DATA ACQUISITIONS
Validating
dcfldd • Use the hash option to designate a hashing algorithm of md5, sha1, sha256, sha384, or sha512
• hashlog option outputs hash results to a text file that can be stored with the image files
acquired data • vf (verify file) option compares the image file to the original medium
WINDOWS VALIDATION METHODS
RAID 5
Similar to RAIDs 0 and 3
Places parity recovery data on each disk
RAID 6
Redundant parity on each disk
RAID 10 (1+0), or mirrored striping
Combination of RAID 1 and RAID 0
Provides fast access and redundancy
RAID 15 (1+5)
Combination of RAID 1 and RAID 5
More costly option
UNDERSTANDING RAID (6 OF 6)
ACQUIRING RAID DISKS (1 OF 2)
US-LATT PRO
Part of a suite of tools developed by WetStone
Can connect to a networked computer remotely and perform a live acquisition of all drives
connected to it
REMOTE ACQUISITION WITH F-RESPONSE
F-Response
Other commercial
acquisition tools
PassMark Software
ImageUSB
ASRData SMART
Runtime Software
ILookIX Investigator
IXimager
SourceForge
PASSMARK SOFTWARE IMAGEUSB
PassMark Software has an acquisition tool called ImageUSB for its OSForensics analysis
product
To create a bootable flash drive, you need:
Windows XP or later
ImageUSB downloaded from the OSForensics Web site
ASR DATA SMART
ASR Data • A Linux forensics analysis tool that can make image files of a
suspect drive
SMART
• Can produce proprietary or raw format images
Capabiliti
• Data reading of bad sectors
• Can mount drives in write-protected mode
• Can mount target drives in read/write mode
Runtime Software offers shareware programs for data acquisition and recovery:
DiskExplorer for FAT and NTFS
Features:
Create a raw format image file
Segment the raw format or compressed image for archiving purposes
Access network computers’ drives
ILOOK INVESTIGATOR IXIMAGER
IXimager
Runs from a bootable floppy or CD
Designed to work only with ILookIX
Can acquire single drives and RAID drives
Supports:
IDE (PATA)
SCSI
USB
FireWire
SOURCEFORGE