2. Module Objectives
• Data Storage Media
• Acquisition Tools
− Software
− Hardware
• Image Formats
• FTK Imager Interface
− File System Support
− File Properties and Interpreters
− Right-click Menu Options
• FTK Imager Functionality
− Previewing and Triage
− Acquisition
− Conversion / Verification
− Custom Content Images
− Mounting Images
− Acquire Memory
3. Data Storage Media
Magnetic
• Floppy Disk
• Hard Drives
• USB, PC Card, etc.
• Zip & Tape Drives
Optical
• CD
• DVD
Alternative Media
• MP3 Players
• Tablets
• Smartphones
• Who Knows What …
15. Software Acquisition Process
Hashing and Verification
The goal is
to make an
Identical
Bit-by-Bit
Image
The goal is
to make an
Identical
Bit-by-Bit
Image
=
16. Image Formats
• Raw-DD (.001)
• SMART (.s01)
• Encase (.e01)
• AFF (.aff)
• AD1 (.ad1)
• ISO/CUE
(.iso/.cue)
Imager Can Read
These Formats
Imager Can
Create These
Formats
26. Custom Content Images
• Can be from multiple
sources
• Can include Unallocated
Space
• Results in an .ad1 format
image
• Can include specific SID(s)