By Bruce Nikkel
Forensic picture acquisition is a vital a part of postmortem incident reaction and proof assortment. electronic forensic investigators gather, guard, and deal with electronic proof to help civil and legal instances; learn organizational coverage violations; unravel disputes; and study cyber attacks.
Practical Forensic Imaging takes a close examine tips to safe and deal with electronic facts utilizing Linux-based command line instruments. This crucial advisor walks you thru the full forensic acquisition procedure and covers a variety of useful situations and events concerning the imaging of garage media.
You'll learn the way to:
practice forensic imaging of magnetic demanding disks, SSDs and flash drives, optical discs, magnetic tapes, and legacy technologies
shield connected facts media from unintended modification
deal with huge forensic photograph documents, garage potential, photo structure conversion, compression, splitting, duplication, safe move and garage, and safe disposal
protect and ensure proof integrity with cryptographic and piecewise hashing, public key signatures, and RFC-3161 timestamping
paintings with more moderen force and interface applied sciences like NVME, SATA convey, 4K-native zone drives, SSHDs, SAS, UASP/USB3x, and Thunderbolt
deal with force defense similar to ATA passwords; encrypted thumb drives; Opal self-encrypting drives; OS-encrypted drives utilizing BitLocker, FileVault, and TrueCrypt; and others
collect usable photographs from extra complicated or tough occasions resembling RAID structures, digital laptop photographs, and broken media
With its targeted specialise in electronic forensic acquisition and facts upkeep, useful Forensic Imaging is a useful source for knowledgeable electronic forensic investigators desirous to enhance their Linux talents and skilled Linux directors desirous to research electronic forensics. this can be a must-have reference for each electronic forensics lab.