官术网_书友最值得收藏!

  • Windows Forensics Cookbook
  • Oleg Skulkin Scar de Courcier
  • 142字
  • 2021-07-02 20:57:43

Drive acquisition in E01 format with FTK Imager

FTK Imager is an imaging and data preview tool by AccessData which allows an examiner not only to create forensic images in different formats, including RAW, SMART, E01, and AFF, but also to preview data sources in a forensically sound manner. In the first recipe of this chapter, we will show you how to create a forensic image of a hard drive from a Windows system in E01 format.

E01 or EnCase's Evidence File is a standard format for forensic images in law enforcement. Such images consist of a header with case info, including acquisition date and time, examiner's name, acquisition notes, and password (optional), a bit-by-bit copy of an acquired drive (consisting of data blocks, verified with its own CRC or Cyclical Redundancy Check), and a footer with MD5 hash for the bitstream.
主站蜘蛛池模板: 缙云县| 巴青县| 清流县| 海丰县| 清苑县| 枝江市| 舞阳县| 九寨沟县| 酉阳| 平武县| 商河县| 离岛区| 勃利县| 安阳县| 健康| 应城市| 云龙县| 集贤县| 贞丰县| 井陉县| 特克斯县| 绵阳市| 太仆寺旗| 永仁县| 和林格尔县| 满城县| 吉安县| 赤城县| 贡嘎县| 德昌县| 凭祥市| 宜章县| 濮阳县| 文登市| 长沙县| 杭州市| 鄂托克前旗| 依兰县| 肥东县| 迭部县| 洪江市|