5 Forensic Duplication
5 Forensic Duplication
5 Forensic Duplication
Computer
Forensics
8 Forensic Duplication
Types of Duplication
• Simple duplication
• Copy selected data; file, folder, partition...
• Forensic duplication
• Every bit on the source is retained
• Including deleted files
• Goal: act as admissible evidence in court
proceedings
Requirements
Requirements
Every Bit?
• It contains firmware
• Complete disk
• Partition
• Logical
Complete Disk Image
Demo: FTK Imager
Demo: FTK Imager
Recovering Deleted Files
• If a suspect attempts to hide data by
• Reinstalling the OS
• Reformatting
• Unallocated Space
• File slack
• Chain of custody
• Boot disk
• Blocks
writing with
software
Image Creation Tools
• winen.exe or winacq.exe