click below
click below
Normal Size Small Size show me how
C702 10%
C702 Data and File forensics
| Term | Definition |
|---|---|
| R-Tools | |
| Acquiring Data on Linux dd | dd Command. use DD to make a complete physical backup of the hard disk. |
| Acquiring Data on Linux dcfldd (1) | dcfldd Command offers functions that are not possible with dd. Hashing on the fly, Status output, flexible disk wipes, Imaging/wipe verify, multiple outputs, split output, piped output |
| Acquiring Data on Linux dclfdd (2) | Bit-stream disk-to-image ProDiscover, EnCase, FTK, TSK, X-Ways, ILook |
| Acquiring Data on Linux dclfdd (3) | Bit-stream disk-to-disk EnCase, SafeBack, Norton Ghost |
| Enable Write Protection on the Evidence Media Hardware write blocker | Installa write blocker device |
| Enable Write Protection on the Evidence Media Software write blocker | Boot the system with the examiner with the examiner's controlled operating system and activate write protection |