30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table<br />

(GPT<br />

disk):<br />

Log<br />

highlights:<br />

Helix3 Pro R3 (Release Date: 30 th , Dec 2009)<br />

02 in<strong>for</strong>mation about the acquisition at least including following: device, start<br />

sector, end sector, type and number <strong>of</strong> errors encountered, and start time and<br />

ALOG-<br />

03<br />

end time <strong>of</strong> acquisition.<br />

The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />

and the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />

function is supported<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />

Device<br />

Source Hashes:<br />

MD5: 7a84a94aae46d34ac61dc26800f6dd19<br />

SHA1: f913fd6832de537c78dc4da881281984daed37f5<br />

/dev/sdb: current max LBA: 156,301,488<br />

/dev/sdb: native max LBA: 156,301,488<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA and DCO are not set<br />

Device Start End #sectors File System<br />

/dev/sdb1 34 262110 262144 Micros<strong>of</strong>t<br />

Reserved<br />

/dev/sdb2 264192 8652799 8388608 NTFS<br />

/dev/sdb3 8652800 12847103 4194304 NTFS<br />

/dev/sdb4 12847104 14944255 2097152 NTFS<br />

/dev/sdb5 14944256 25380863 10436608 NTFS<br />

/dev//sdb6 25380864 156299264 130918400 NTFS<br />

Created By Helix3 Pro 2009R3<br />

OS Name Windows XP<br />

OS Patch Service Pack 3<br />

Administrator True<br />

physical True<br />

size 80023749120<br />

serialnumber 3.42<br />

firmware ST380817<br />

type Fixed hard disk<br />

Whole<strong>Disk</strong> True<br />

Acquire Format: RAW<br />

Acquisition Start: 2010-09-17 01:44:28<br />

Acquisition Stop 2010-09-17 06:01:05<br />

Output File(s):<br />

G:\Image\Helix3-GUID.001<br />

G:\Image\Helix3-GUID.002<br />

………………………<br />

G:\Image\Helix3-GUID.038<br />

Verification: Passed<br />

Hash(es):<br />

MD5: 7a84a94aae46d34ac61dc26800f6dd19<br />

SHA1: f913fd6832de537c78dc4da881281984daed37f5<br />

246

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!