click below
click below
Normal Size Small Size show me how
C702 10%
C702 Data and File forensics
Term | Definition |
---|---|
R-Tools | |
Acquiring Data on Linux dd | dd Command. use DD to make a complete physical backup of the hard disk. |
Acquiring Data on Linux dcfldd (1) | dcfldd Command offers functions that are not possible with dd. Hashing on the fly, Status output, flexible disk wipes, Imaging/wipe verify, multiple outputs, split output, piped output |
Acquiring Data on Linux dclfdd (2) | Bit-stream disk-to-image ProDiscover, EnCase, FTK, TSK, X-Ways, ILook |
Acquiring Data on Linux dclfdd (3) | Bit-stream disk-to-disk EnCase, SafeBack, Norton Ghost |
Enable Write Protection on the Evidence Media Hardware write blocker | Installa write blocker device |
Enable Write Protection on the Evidence Media Software write blocker | Boot the system with the examiner with the examiner's controlled operating system and activate write protection |