SCI 4201 Practicals: Bethel Chaka N0161068D May 13, 2020

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

SCI 4201 Practicals

Bethel Chaka N0161068D


May 13, 2020

1
1. You’re investigating a case involving a 2 GB drive that you need
to copy at the scene. Write one to two pages describing three op-
tions you have to copy the drive accurately. Be sure to include your
software and media choices.

• Solution

Acquiring the data primarily requires making a copy of the hard drive
bit by bit. Acquisition of data requires collecting data to solve the case
from the location of the crime. Evidences are stored as image file in one
of three formats in the computer forensics tool. Two are open source and
the third is proprietary. Proprietary format is different, as each vendor has
different unique features. The data collection is carried out in four ways:

• Create disk to image file

• Creating disk-to-disk copy

• Creating logical disk to disk or disk-to-data file

• Creating a sparse copy of a folder or file

Disk Imaging
The stand-alone drive imaging software ”Forensic Imager” is included in
the Recover My Files Installation tab. Forensic Imager is a program based
on Windows that acquires a sectoral copy (”image”) of a drive in one of
the following common forensic file formats:

1. DD /RAW (Linux “Drive Dump”)

2. AFF (Advanced Forensic Format)

2
3. E01 (EnCase) [Version 6.xx format]

Running Forensic Imager


Forensic Image is run from the Recover My Files drop down menu by se-
lecting the “Disk Image” option. Or by selecting the Disk Imager shortcut
from the “Windows Start then All Programs then Recover My Files v5 then
Disk Imager” shortcut.

You might also like