Wired_2.0_CREATE YOUR ULTIMATE LEARNING ENVIRONMENT_JCON_16052024
How to Use Write Blocker for Imaging Pen drive
1. Write Blocker Device Forensic UltraDock
Aim: How to Use Write Blocker for Imaging Pen drive
Requirements:
1. Forensic UltraDock Kit
2. Suspected pen Drive
3. PC-System
Description:
Hardware write-blockers commonly are used when acquiring a
suspect's media. When a drive is connected to a Microsoft Windows
operating system, changes are made to that drive. These hardware
write-blockers will prevent Windows or other operating systems
from writing to that drive.
Features:
• Four separate host attachment options (USB 3.0, FireWire 800,
FireWire 400, and eSATA) for compatibility with virtually any
computer
• Multiple LEDs indicate operational status, including disk activity,
hidden area detection, error state, and the status of power input and
output
2. • LCD menu allows user to configure settings and view information
on attached drives
• Detects and indicates hidden areas (HPAs or DCOs) found on hard
drives
• Able to create or remove HPAs and DCOs
• All-aluminum case for rugged durability and excellent heat
dissipation
6. Figure 5 Open In view
Figure 6 Source View
Procedure:
1. Check Requirements Like Windows/Linux System, Write Blocker, Suspected Drive
2. Let Start Write Blocker Connected with Power cable and switch on
Figure 7 Power Plug in write Blocker
7. Figure 8 Write Blocker View
3. Source Connected Suspected any Drive like Hardware, Pen drive based on given
Ports
Figure 9 estata drive, Power out connect Suspected Laptop Hard drive
Figure 10 Source device( Suspected Laptop hardware) connected to Forensic Write blocker with sata cable
4. Next Write block usb 3.0 port to System usb port connection with the cable
8. Figure 11 Write blocker usb 3.0 port to Destination Our forensics System with os(Window or Mac or Linux)
5. Look at Suspected drive will be showing or not in a system, following screenshot
describing not showing any device is connected, but we connected with all
precision.
Figure 12 write blocker access allow mode off (write blocker rearview have on ond off button)
9. 6. Look at Forensic ultradock box middle have Main power on/off button forgot to on,
Now switch on that display show device information, Following Screenshot and
open system is weather check connected device to system
Figure 13 Before switch off mode
10. 7. After Pen Drive Connected to the system, then open pen drive list all folder and files
11. 8. Check write blocker working or not proper, we will create folder and file with text
content.
9. Delete folder from pen drive
12. 10. After Delete now add some text into file (New text Document). Next step turn off
Write Blocker(Forensic UltraDock ).
11. Ultradock switch main button turn off and on once again check File is here or delete
is view on pen drive. After We Can investigate proper method.
13. Conclusion:
Successfully Tested, use write blocker suspected dive data is temper not possible is
here. Then forensic duplication process, we can use write blocker to take images from a
suspected drive using FTK imager next process.