30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

This procedure outlines the process <strong>of</strong> a disk imaging acquisition <strong>of</strong> the tool FTK<br />

Imager.<br />

4.5.1 Prerequisites<br />

1. Windows XP Pr<strong>of</strong>essional with Service Pack 3 is installed in the system or<br />

Windows 7 with latest system updates installed<br />

2. Minimum data storage requirement <strong>for</strong> the program is met<br />

4.5.2 Acquisition – FTK Imager (Windows Version - Common in most Test<br />

Scenarios)<br />

1. Connect the test hard drive to the Windows machine using the specified<br />

physical interface. Connect to the hardware writeblocker if the test case is<br />

required.<br />

2. Log on the computer with administrator privilege.<br />

3. Start FTK Imager (Under Windows 7, run the program as administrator)<br />

4. Click “Add Evidence Item” and select physical drive<br />

5. Choose the test drive and click Finish<br />

6. Acquire Entire drive or single partition<br />

a) Right click the physical drive and select “Export disk image”<br />

b) Right click the partition that need to be acquired and select “Export<br />

disk image”<br />

7. Select verify image, precalculate progress and create directory listings and<br />

Add image and choose image type either dd, E01 or Smart.<br />

8. Input Case Number, Evidence Number, Description, Examiner and Notes.<br />

9. Choose destination folder and input the desired image filename. Change<br />

Image fragment size if necessary.<br />

10. Then click finish to start disk acquisition.<br />

11. Wait until FTK Imager indicates the acquisition progress is completed.<br />

4.1 Acquisition – AIR<br />

This procedure outlines the process <strong>of</strong> the disk imaging acquisition <strong>of</strong> the tool AIR.<br />

4.6.1 Prerequisites<br />

1. Uudecode program must be installed (use command “which uudecode” to<br />

verify whether uudecode is installed)<br />

146

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!