官术网_书友最值得收藏!

How to do it...

The steps for drive acquisition in RAW format using dc3dd are as follows:

  1. Open Windows Command Prompt, change directory (you can use cd command to do it) to the one with dc3dd.exe, and type the following command:
dc3dd.exe if=\\.\PHYSICALDRIVE2 of=X:\147-2017.dd hash=sha256
log=X:\147-2017.log
  1. Press Enter and the acquisition process will start.

Of course, your command will be a bit different, so let's find out what each part of it means:

  • if - stands for input file. Originally, dd was a Linux utility, and in case you didn't know, everything is a file in Linux. As you can see in our command, we put the physical drive 2 here (this is the drive we wanted to image, but in your case it may be another drive, depending on the number of drives connected to your workstation).
  • of - stands for output file. Here, you should type the destination of your image in RAW format. In our case, it's X:\ drive and 147-2017.dd file.
  • hash - as has already been said, DC3DD supports four hashing algorithms: MD5, SHA-1, SHA-256, and SHA-512. We chose SHA-256, but you can choose whichever one you like.
  • log - here, you should type the destination for the logs. You will find the image version, image hash, and so on in this file once acquisition is completed.
主站蜘蛛池模板: 山阳县| 海宁市| 大新县| 闵行区| 广州市| 凤山市| 绥阳县| 兴义市| 喀喇沁旗| 勐海县| 新昌县| 仁寿县| 北辰区| 荆州市| 若羌县| 济南市| 凤凰县| 静海县| 汾西县| 巩义市| 调兵山市| 荔浦县| 错那县| 扎鲁特旗| 西乌珠穆沁旗| 宝鸡市| 出国| 富裕县| 四子王旗| 大化| 鹤庆县| 锦屏县| 西充县| 武宣县| 西峡县| 尉犁县| 嘉禾县| 诏安县| 新巴尔虎右旗| 通河县| 海口市|