IMAGE ACQUISITION



              - Nithin
Forensic Process

• Acquisition or Imaging
• Analysis
• Reporting
Forensic Process
• Acquisition or Imaging
  – Sector level duplication
  – Hashing
• Analysis
• Reporting
Disk Imaging
• Sector by sector copying
• Archive files
  – Meta data,
  – File directory structure
• File Formats
  – Information to 0’s and 1’s
• Write blocker
  – Native
  – Tailgate
• Cluster
  – A single sector, on a standard hard drive is 512
    bytes
  – Group of sectors is clusters
  – In a Windows pc a cluster has 8 sectors (4kB)
  – 1 cluster is the smallest file size that a drive can
    handle
Live Working on FTK imager
Thank you 

Computer Image acquisition