Bruce Nikkel 2_1_acquisition_tools.pdf
Wähle die Ordner aus, zu welchen Du "Bruce Nikkel 2_1_acquisition_tools.pdf" hinzufügen oder entfernen möchtest
What is important of "forensically sound" acquisition according to the NIST Computer Forensic Tool Testing (CFTT) standard:
What is done to preserver the integrity of evidence and why is it done
Can be a seperate step, or is built into forensic tools
Dataintegrity is guarantied through cryptographic hashes.
What commands can you use to double check the evidence drive.
What information about an evidence drive is taken?
Smart data is digital information that is formatted so it can be acted upon at the collection point before being sent to a downstream analytics platform for further data consolidation and analytics.
What should you always do when dealing with an evidence drive?
Always double-check source and destination devices!!!
what does the dd command do?
The dd command:
Copying disk sectors:
DD = "Dangerous and Deadly"
What are some forensic variations of the dd command and what aditional features do they have?
Forensic acquisition tools based on dd:
Additional features they include:
What is done when forensic images are made?
Forensic images are HUGE
Seeking = searching
Institut für Banking und Finance
Verlag, Versandbuchhandlung, Schulbelieferung