Welcome to computer forensic portal - your online resources to all computer foreniscs
 
Knowledge Articles
Books Database
Legal Cases
Forensic Dictionary
PDF documents
Web Resources
FAQ

 

Image Acquisition
Page 1
Page 2
Page 3
Page 4
 
Computer Forensic Tools
Expert Witness
Helix (Windows)
Helix (Linux)

 

  Home > Knowledge Articles > Image Acquisition (Windows)

Image Acquisition (Windows)

2. Select the source to make an image copy and click Next.

  • If you are doing bit-stream copy, select Physical Drive;
  • If you are doing logical copy, select Logical Drive;
  • If you are doing a copy of an image file, select Image File;
  • If you are doing a copy of a folder, select Contents of a Folder.

3. Select the drive you wish to image and click Next.

4. In Create Image Dialog,

  • By selecting “Verify Images after they are created”, you can compare the stored hashes of your image.
  • By selecting “Create directories listings…”, you can list the entire contents of your images with path, creation dates, whether files were deleted, and other metadata. The list is saved in a tab-separated value format.

Click Add, and select the image type,

  • Raw(dd) : It is not compressed, make sure you have enough space for the full image.
  • SMART and E01: They are proprietary formats for use in SMART forensic suite and Encase Forensic Suite respectively.

[back - page 1] [continue - page 3]

 

© 2009
Computer Forensics Portal
All Rights Reserved

Disclaimer | Privacy Policy

Home | Contact | Sitemap

Knowledge Articles | Books Database | Legal Cases | Forensic Dictionary | Web Resources | Frequently Asked Questions