Guide to Computer Forensics and InvestigationsĤ Capturing an Image with AccessData FTK Imager (continued) Included on AccessData Forensic Toolkit View evidence disks and disk-to-image files Makes disk-to-image copies of evidence drives At logical partition and physical drive level Can segment the image file Evidence drive must have a hardware write-blocking device Or the USB write-protection Registry feature enabled FTK Imager can’t acquire drive’s host protected area 67335_PPT_ch04.ppt : pages 26~32 Guide to Computer Forensics and Investigationsģ Capturing an Image with AccessData FTK Imager (continued) 1 Hands-on: Capturing an Image with AccessData FTK ImagerĢ Capturing an Image with AccessData FTK Imager
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |