30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7. Keep setting “noerror, sync” as Conversion.<br />

8. Click start to start the acquisition<br />

9. Wait until AIR indicates the acquisition progress is completed.<br />

10. Save the Log file to an external drive as backup.<br />

4.2 Acquisition – Helix 3 Pro<br />

This procedure outlines the process <strong>of</strong> a disk imaging acquisition <strong>of</strong> the tool Helix 3<br />

Pro.<br />

4.7.1 Prerequisites<br />

1. CD/DVD drive is properly setup and ready to use<br />

2. Windows XP Pr<strong>of</strong>essional with Service Pack 3 is installed in the system or<br />

Windows 7 with latest system updates installed<br />

3. Minimum data storage requirement <strong>for</strong> the program is met<br />

4.7.2 Acquisition – Helix 3 Pro (Common in most Test Scenarios)<br />

1. Connect the test hard drive to the Windows machine using the specified physical<br />

interface. Connect to the hardware writeblocker if the test case is required.<br />

2. Boot from the Helix 3 Pro Live CD or start Helix 3 from the Windows<br />

environment<br />

3. Run Helix 3<br />

4. Choose the Source drive or partition from the device list.<br />

5. Click Acquire tab<br />

a) Select the output type (Usually is RAW <strong>for</strong>mat but EnCase <strong>for</strong>mat is<br />

used in certain test cases)<br />

b) Input Case name, Examiner, Case Number, Item number, Description<br />

and Notes<br />

c) Choose 2GB default segmentation and Read Size 32768<br />

d) Select MD5 and SHA1 as hash protocol<br />

e) Select destination drive<br />

f) Start the acquisition<br />

g) Wait until Helix 3 Pro indicates the acquisition progress is completed.<br />

4.3 Verification <strong>of</strong> Acquired Image (Common in most Test Scenarios)<br />

148

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!