官术网_书友最值得收藏!

  • Windows Forensics Cookbook
  • Oleg Skulkin Scar de Courcier
  • 142字
  • 2021-07-02 20:57:43

Drive acquisition in E01 format with FTK Imager

FTK Imager is an imaging and data preview tool by AccessData which allows an examiner not only to create forensic images in different formats, including RAW, SMART, E01, and AFF, but also to preview data sources in a forensically sound manner. In the first recipe of this chapter, we will show you how to create a forensic image of a hard drive from a Windows system in E01 format.

E01 or EnCase's Evidence File is a standard format for forensic images in law enforcement. Such images consist of a header with case info, including acquisition date and time, examiner's name, acquisition notes, and password (optional), a bit-by-bit copy of an acquired drive (consisting of data blocks, verified with its own CRC or Cyclical Redundancy Check), and a footer with MD5 hash for the bitstream.
主站蜘蛛池模板: 理塘县| 宁强县| 鄂温| 京山县| 嵩明县| 高尔夫| 乌兰察布市| 上思县| 邵阳县| 莱西市| 汤阴县| 绩溪县| 定陶县| 洪雅县| 洛阳市| 塔河县| 深水埗区| 大英县| 元氏县| 广南县| 双峰县| 镇赉县| 富民县| 建宁县| 尚志市| 宁晋县| 武功县| 莲花县| 马关县| 固阳县| 开远市| 枣庄市| 景泰县| 新竹县| 邵武市| 钦州市| 仁布县| 从江县| 丰镇市| 辽源市| 辽中县|