30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

MD5 verification hash: f7c2c38630b0c995732a87cce003dcca<br />

SHA1 verification hash: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed<br />

Bytes per Sector: 512<br />

Sector Count: 2,104,452<br />

Image Type: E01<br />

Acquired on OS: Windows 200x<br />

Acquired using: ADI2.9.0.13<br />

Acquire date: 8/10/2010 3:40:11 PM<br />

System date: 8/10/2010 3:40:11 PM<br />

Unique description: untitled<br />

Source data size: 1027 MB<br />

Sector count: 2104452<br />

MD5 checksum: f7c2c38630b0c995732a87cce003dcca<br />

SHA1 checksum: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed<br />

Acquisition started: Wed Aug 11 03:48:23 2010<br />

Acquisition finished: Wed Aug 11 03:48:55 2010<br />

Segment list:<br />

G:\new\Test005-AltFor-FTK\Test005-FTK-E01toSmart.s01<br />

Verification started: Wed Aug 11 03:48:55 2010<br />

Verification finished: Wed Aug 11 03:49:14 2010<br />

MD5 checksum: f7c2c38630b0c995732a87cce003dcca : verified<br />

SHA1 checksum: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed :<br />

verified<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-09 PASSED ALOG-02 PASSED<br />

ALOG-03 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification<br />

hashes and the hash <strong>of</strong> the original EnCase E01 image.<br />

1.22 TC-11-DD_E01<br />

Test Case TC-11-DD_E01 (FTK Imager 2.9.0.1385)<br />

Test &<br />

Case<br />

Summary:<br />

Convert an existing image file to another image file <strong>for</strong>mat<br />

Notes: Convert image from DD to E01 <strong>for</strong>mat<br />

Assertion: AFR-03 The tool operates in an execution environment<br />

AFR-09<br />

ALOG-01<br />

ALOG-02<br />

ALOG-03<br />

If there are unresolved errors reading from a digital source,<br />

then the tool uses a benign fill in the destination object in<br />

place <strong>of</strong> the inaccessible data.<br />

If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />

the in<strong>for</strong>mation is accurately logged in the log file.<br />

The tool display correct in<strong>for</strong>mation about the acquisition to<br />

the user.<br />

The tool display correct in<strong>for</strong>mation regarding to the<br />

acquisition to the user and the in<strong>for</strong>mation displayed is<br />

consistent with the log file if the log file function is<br />

191

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!