<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Acquisition Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<atom:link href="https://compute-forensics.com/tag/data-acquisition/feed/" rel="self" type="application/rss+xml" />
	<link>https://compute-forensics.com/tag/data-acquisition/</link>
	<description></description>
	<lastBuildDate>Tue, 03 Jul 2018 18:10:17 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://compute-forensics.com/wp-content/uploads/2018/06/cropped-cropped-CF-1-32x32.png</url>
	<title>Data Acquisition Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<link>https://compute-forensics.com/tag/data-acquisition/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What is Imaging in Computer Forensics and E-Discovery?</title>
		<link>https://compute-forensics.com/what-is-computer-forensic-imaging/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Thu, 28 Jun 2018 18:13:51 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Data Acquisition]]></category>
		<category><![CDATA[Data Collection]]></category>
		<category><![CDATA[Forensic Imaging]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Physical Image]]></category>
		<category><![CDATA[Targeted Collection]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1827</guid>

					<description><![CDATA[DISCLAIMER Only a qualified computer forensics expert from a company such as Compute Forensics should be selected to perform forensic data collection. You can call us on +44 (0)203 5989658, email us at expert@compute-forensics.com or &#8216;Live Chat&#8217; to a computer forensics expert witness by clicking on the red tab at the left of the website. Compute Forensics offers a global collection service]]></description>
										<content:encoded><![CDATA[<h3>DISCLAIMER</h3>
<p>Only a qualified computer forensics expert from a company such as Compute Forensics should be selected to perform forensic data collection. You can call us on +44 (0)203 5989658, email us at <a href="http://mailto%40expert@compute-forensics.com/" rel="nofollow noopener">expert@compute-forensics.com</a> or &#8216;Live Chat&#8217; to a <a href="http://compute-forensics.com/?portfolio=computer-forensics" rel="nofollow noopener">computer forensics expert witness </a>by clicking on the red tab at the left of the website. Compute Forensics offers a global collection service for e-Discovery firms, Digital Forensic firms and businesses under litigation. <a href="http://compute-forensics.com/contact-us/" rel="nofollow noopener">Compute Forensics</a> can provide training and equipment to IT departments that require the collection skills themselves as to give a lightning response that is needed when the need arises.</p>
<h3>Introduction</h3>
<p>This article is designed to be a general overview of the actions, programs and techniques used in data collection before scenarios such as a digital investigation of a recently departed employee or for an <a href="http://compute-forensics.com/?portfolio=email-discovery" rel="nofollow noopener">e-Discovery</a> litigation hold.</p>
<h3>What is Forensic Imaging?</h3>
<p>Forensic imaging, in a nutshell, is the act of gathering data in a court accepted fashion from digital media to a <a href="http://veracrypt.codeplex.com/" rel="nofollow noopener">Veracrypted</a> encrypted output device where possible. That data may come from a live system, a dead PC, DVD, iMac, USB disk, X-Box or remote mailbox. Those are just a few examples.</p>
<p>Typically, the source media should be placed into a blocked state when being read and the data outputted to an attached destination disk with read/write access. It is essential contiguous notes of the system and steps taken are made while the imaging is taking place. The forensic imaging should be done by a certified, experienced <a href="http://www.linkedin.com/in/computerforensicsexpertwitness" rel="noopener">digital forensics expert witness</a> or at least an individual with collection training and IT knowledge.</p>
<p>On certain occasions blocking writes to the source media may not be possible such as if you are presented with a live system server or an encrypted system that is discovered switched on. In these instances, the image must be taken live as not to disturb a server or re-encrypt an unlocked disk.</p>
<p>In addition to noting the collection process, it is important to note the physical location of the evidence and store it in a compliant manner and always gain signatures when handing over data.</p>
<p><strong>Tip: </strong>As a rule, if the system is switched off leave it that way. If it is changed on leave, it switched on but take the computer, laptop or phone off the network and connected to power. For a computer that may mean unplugging the network cable, sliding a switch to ensure WIFI is off, pulling out a dongle, popping out a network card or disabling networking in the control panel of the operating system. For a tower computer, it may mean just pulling out the Ethernet cable.</p>
<h3>What is a Physical Forensic Image?</h3>
<p>A physical forensic image is a full &#8216;bit for bit&#8217; copy of the particular media. This includes every byte of data from the live file system to the unallocated deleted areas of the disk.</p>
<p>The forensic image may be outputted in some formats such as a simple format agnostic raw dd image format, the common EnCase E01 evidence image or the less common Advanced Forensics Format (AFF). If you wrote this forensic image back to a disk in its raw format (FTK has this functionality) with the same capacity, it would be identical in every way to the original. From this image, a computer forensic analysis would be conducted as not to risk damaging the original.</p>
<p>I have personally experienced occasions where forensic software wasn&#8217;t used to collect the data for some reasons like a RAID wasn&#8217;t being recognised on older systems or the disk was not being read in Windows. In these instances, something akin to a bootable <a href="http://clonezilla.org/clonezilla-live.php" rel="nofollow noopener">Clonezilla Live</a> distro may be used to produce the image. When doing so always explain your reasoning in notes and find the verify or MD5 hash the result if necessary. Getting something is better than walking away with no data at all. Again this should always be done by a qualified person that is well versed in <a href="http://compute-forensics.com/" rel="nofollow noopener">forensic imaging</a>.</p>
<h3>What is a Logical Forensic Image?</h3>
<p>A logical forensic image or skeleton image is a particular copy of certain files from a source. Many programs can produce logical images: Stefan Fleischmann&#8217;s excellent <a href="http://www.x-ways.net/imager/" rel="nofollow noopener">X-Way&#8217;s Imager</a>, the superb and free <a href="http://accessdata.com/product-download/digital-forensics/ftk-imager-lite-version-3.1.1" rel="nofollow noopener">FTK Imager</a> or new on the scene <a href="http://www.magnetforensics.com/acquire-community/" rel="nofollow noopener">Magnet&#8217;s Acquire software</a> can be used to do this in a Windows environment.</p>
<p>A logical acquisition is the option to use if the digital expert requires a targeted collection for litigation reasons, just a few files of interest are needed, or the client collect wishes you to collect from one or more custodian&#8217;s user profiles from a server that may have many users.</p>
<p>In an active state, <a href="http://marketing.accessdata.com/ftkimagerlite3.1.1" rel="nofollow noopener">FTK Imager Lite</a> as shown in <strong>Fig 1, </strong>can be executed from the destination disk on the computer you wish to extract from as not to write to the live computer by installing software to the source. A custom content list can be built into the programs user interface, and a logical forensic image file is thus produced.</p>
<p>FTK Imager can be used to mount forensic images to view in Windows Explorer, build custom content images of live machines, image RAM (random access memory) from a live system, view and export from Linux/Mac/Windows filesystems and most commonly forensically image a hardware or software writeblocked device to an external disk. FTK Imagers only drawback is when an examiner images a damaged disc the software fills in the unreadable sectors with 0&#8217;s. Not attempting to read the drive is unacceptable when a data recovery solution such as &#8216;<a href="http://www.gnu.org/software/ddrescue/" rel="nofollow noopener">ddrescue</a>&#8216; may recover a whole email collection where the forensic tool fills what it can&#8217;t read with 0&#8217;s. In an investigation or legal hold, every byte counts! I have been the examiner that has acquired 100% of an image where others had to explain in court why some sectors weren&#8217;t imaged.</p>
<h3>Fig 1 FTK Imager Version 3.3.0.5 the Crème De La Crème of Forensic Imaging Tools</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C4E12AQF1Hr2Ve6VlGw/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=OT-y1xyC4elrOewQLkMfpVUchbPEDIYvFtv-oZ3PdP4" width="744" data-media-urn="urn:li:digitalmediaAsset:C4E12AQF1Hr2Ve6VlGw" data-li-src="https://media.licdn.com/dms/image/C4E12AQF1Hr2Ve6VlGw/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=OT-y1xyC4elrOewQLkMfpVUchbPEDIYvFtv-oZ3PdP4" /></p>
<p>On a live Mac you may want to produce a full image using a bootable Linux forensics distribution such as <a href="http://www.caine-live.net/" rel="nofollow noopener">Caine </a>then go on to build a list from that main image onsite should the client not want all the data walking off site. There are other solutions like BlackBag&#8217;s convenient <a href="http://www.blackbagtech.com/software-products/macquisition.html" rel="nofollow noopener">MacQuisition</a>.</p>
<h3>Verification MD5 and SHA1</h3>
<p>The verification information is hardcoded inside the metadata of the image in the case of most advanced forensic image formats such as E01, AD1, and AFF. A log is produced by any decent imaging software with a verification sum generated for the forensic image to signify the image is identical to the original. Verification is done so that the professional examining the image can be sure the image hasn&#8217;t changed since it was taken by checking the MD5 or SHA1 hash sum or other before commencing the investigation.</p>
<p><strong>Fig 2 </strong>displays an example log auto-generated by AccessData&#8217;s FTK Imager. The imaging log gives forensic experts some information about the physical capacity of the disk, serial number and some of the notes I have used. In this case, the image was a server that was running a virtual machine. FTK imager was run live in this instance in the emulated environment, and the image was outputted to the emulated physical disk. Another option is shutting down the virtual machine image and logically copying and verifying the file or indeed the whole of the servers physical disk. Shutting down a server may cause financial loss to a firm and disruption if the server is in use. If it is on image the machine while it is in that state while taking notes, that is my recommendation.</p>
<h3>Fig 2 &#8211; Example Forensic Imaging Log File Automatically Generated by FTK Imager Lite V3.1.1.8</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQEtNhRI4xwPrw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4Q5ZAnYNYo3t6CRvGL6HqvI2h0hIqO3-WNCMMf5xu24" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQEtNhRI4xwPrw" data-li-src="https://media.licdn.com/dms/image/C5612AQEtNhRI4xwPrw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4Q5ZAnYNYo3t6CRvGL6HqvI2h0hIqO3-WNCMMf5xu24" /></p>
<p><strong>Email E-Discovery Collection</strong></p>
<p>Anyone collecting emails should be sure that emails on the local computer mailbox match the server. If they don&#8217;t then it is good practice to receive from both anyway and let the software de-duplicate the items, so you obtain a complete picture of the emails in the forensic search. Computers were after all invented to take the labour out of tasks.</p>
<p>Emails can appear in many forms (Lotus Notes NSF archives, Microsoft PST/OST&#8217;s, or individual EMLX or MSG files) and may not even reside on the custodian&#8217;s hard disk or smartphone under investigation. Other places they could be discovered are on enterprise servers, as a fragment in the deleted areas of a hard disk or even on the cloud via services such as Gmail for business or Microsoft 365. The email archive may also carry encryption so you may get a Lotus Notes NSF email archive file; without the unlock ID and a tool to open you will run into trouble, which goes for password locked PST&#8217;s too.</p>
<p>A computer forensic collection of emails may be as simple as collecting a PST email archive file that resides locally on an individual&#8217;s laptop, server or user share.</p>
<p>A more complex instruction may need the collection of specific emails that contain only certain keywords on a Microsoft Exchange server while keeping the integrity of the email attachment/mailbox structure. In these more complex situations an <a href="http://www.linkedin.com/in/computerforensicsexpertwitness" rel="noopener">E-Discovery collection expert</a> and your client may need to cough up for <a href="http://sherpasoftware.com/" rel="nofollow noopener">Discovery Attender</a> by Sherpa Software, this excellent program plugs into your exchange server and can search, filter and extract onsite. You could also attach FTK with an enterprise agent or even image the whole disk and search from that image onsite.</p>
<p>I have created a summary guide below of the best tools in my experience in email E-Discovery collection:</p>
<h3>Summary of Email Formats and Best Tools for E-Discovery Email Collections</h3>
<ul>
<li><strong>Local PST/OST </strong>Just logically collect an image using FTK Imager or similar. Be sure to hash verify the collected items if copied and make notes!</li>
<li><strong>Webmail such as Gmail/Hotmail/Yahoo/365 Etc </strong>Use <a href="https://www.vound-software.com/individual-solutions#intella-pi" rel="nofollow noopener">Intella&#8217;s PI </a>or the chopped starting at $100 for a 10GB case limit. Using IMAP settings (and permission!) you can collect the whole remote email archive as the binary file and export as a PST file. All these actions carry a full audit log. Many webmail providers such as Gmail have a built-in option to backup and download the whole archive; you may also consider this.</li>
<li><strong>Microsoft Exchange Database </strong>It is possible to just download the whole EDB file and process in FTK 5.6 the full version or later. You could export different custodians as a PST, search, and filter if needed. If you need a few custodians, then something like <a href="http://www.messageops.com/software/" rel="nofollow noopener">MessageOps</a> is convenient. You can install the software on the server, and with admin, credentials run through and select the custodians you wish to export from. The results are outputted as nicely packaged PST&#8217;s along with a log file for verification. Dated indigenous X-merge can also export mailboxes as a PST, but it has a 2GB limit and can be a pain in more extensive collections.</li>
<li><strong>Lotus Notes </strong>The mailbox can be exported from the custodian machine in its entirety in the GUI options of the mail user interface. This approach is great if you have a few especially the admin ID file that contains the decryption keys. Then Proofinder or FTK 5.6 or later can be used to mount and read these archives. You may want to collect direct from the server. In the live environment, you may find the archives don&#8217;t copy. Use <a href="http://www.codesector.com/teracopy" rel="nofollow noopener">Teracopy</a> or Robocopy or something similar to copy stubbornly locked files in a live setting. It is quite likely Samsung, or similar doesn&#8217;t want its <a href="http://www-03.ibm.com/software/products/en/notesanddominofamily" rel="nofollow noopener">Lotus IBM Domino </a>database of 1000 users shut down for 20 hours while it is being imaged! If you have never encountered Lotus Notes before it is because it is antiquated and belongs in the dustbin of history; you needn&#8217;t a Delorian or the Doc to go back in time a few minutes in the dated GUI with fool anyone into thinking it is 1994!</li>
<li><strong>Loose or Deleted Emails </strong>These can be recovered from the server or local by using a <a href="http://compute-forensics.com/?portfolio=data-recovery" rel="nofollow noopener">data recovery</a> program such as the ugly but effective <a href="http://www.cgsecurity.org/wiki/PhotoRec" rel="nofollow noopener">photorec</a> as shown below <strong>Fig 3</strong>. Data Recovery should be made from a previously produced forensic image. If an image is not possible an experienced <a href="http://compute-forensics.com/?portfolio=email-discovery" rel="nofollow noopener">computer forensics collection</a> expert would run photorec live from an external disk and output the data to that same external disk. Emails may also be logically recovered from the email admin interface or reside on the server even though they have been deleted from the custodian&#8217;s machine.</li>
</ul>
<p><strong>Warning: Do not install data recovery software to the drive you wish to recover from or worse still output the retrieved data to the source drive.</strong></p>
<h3>Fig 3 &#8211; PhotoRec TestDisk&#8217;s Beautiful and Modern User Interface</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQG_NsBzFB2PPw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=9bBLPZlWS3j6UduFQoI2-PxPq_gGq6BigompMx-WE40" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQG_NsBzFB2PPw" data-li-src="https://media.licdn.com/dms/image/C5612AQG_NsBzFB2PPw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=9bBLPZlWS3j6UduFQoI2-PxPq_gGq6BigompMx-WE40" /></p>
<h3><strong>Physically Forensic Imaging Using a Hardware Writeblocker</strong></h3>
<p>Many Computer Forensic companies such as Compute Forensics choose to use a hardware write blockers in many instances. A writeblocker is just a device that halts any writes to the disk from the forensic examination system when copying or viewing. This is shown in <strong>Fig 4</strong>. A computer forensics examiner would then go on to attach this device to a USB 3.0 socket on the examination computer&#8217;s USB 3.0 port for optimum speed. Making sure the evidence disk is in &#8216;Locked Mode&#8217; it can be attached to the device. The disk should then show up in Windows Explorer and FTK Imagers &#8216;Add Evidence&#8217; GUI option. The device <em>should </em>now be safe as it is now attached to a hardware writeblocker.</p>
<p>Writeblocking devices used to cost £1000&#8217;s but recently Compute Forensics discovered a decent one built by CoolGear. The Coolgear forensic imaging device has USB 3.0 support and images 2.5&#8243; and 3.5&#8243; sizes of SATA drives. You can pick one of these up for £40.00. I, Alistair Ewing, have tested the CoolGear forensic writeblocker and am content with the performance. It is fast and reliable.</p>
<h3><strong>Imaging Bottlenecks</strong></h3>
<p>The device will only read/copy as fast as the slowest component. On average it takes 4-8 hours for one disk to complete despite companies boasting 500mbs second speeds the device will image anywhere from 1mbs to 80mbs-100mbs. A skilled examiner can copy up to 8 drives at once, much like spinning plates. Collection costs can start at around the £700 a day mark dependant. If you are a company instructing us, please don&#8217;t complain if your rickety 15-year-old IDE disk is taking too long to copy!</p>
<h3><strong>Fig 4 &#8211; CoolGear USB 3.0 Forensic Writeblocker Attached to a 3.5&#8243; SATA Hard Disk Drive</strong></h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQHiavegSls5XA/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=HW54MVmsnkVMT6r-yeCeVyDoR4Rlb-ANM1irRMN4jV0" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQHiavegSls5XA" data-li-src="https://media.licdn.com/dms/image/C5612AQHiavegSls5XA/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=HW54MVmsnkVMT6r-yeCeVyDoR4Rlb-ANM1irRMN4jV0" /></p>
<h3><strong>Forensic Imaging Using any SATA/IDE to USB Adaptor and Software Blocking</strong></h3>
<p>Another unorthodox method I have used in the past when the drive attached to the write blocker won&#8217;t read, or you need a special adapter that isn&#8217;t IDE or SATA. This method uses a software blocker and a USB to SATA, IDE, memory card or whatever adaptor. Make sure the destination drive is a USB 3.0 external drive for speed. A software writeblocking program is used in this instance. Usage is simple but also easy to screw up.. Royally! The steps are:</p>
<p><strong>1)</strong> Plug in your destination drive.</p>
<p><strong>2)</strong> Start Ratool or Thumbscrew and select &#8216;Block USB Storage Devices&#8217; and then apply changes.</p>
<p><strong>3)</strong> Plug in a test USB disk and try and delete format it. Windows shouldn&#8217;t allow writing access to this disk.</p>
<p><strong>4)</strong> If it does repeat step <strong>2) </strong>&amp;<strong> 3) </strong>until the drive is blocked. When blocked it is safe to plug in the USB disk and adapter in the port that you plugged your test device into the system.</p>
<p><strong>5) </strong>Now you should have your destination writable (anything previously plugged in will be writeable too) and your evidence USB stick, Drive or Card plugged in but blocked.</p>
<p><strong>6)</strong> Use your favourite imaging software such as <a href="http://accessdata.com/product-download/digital-forensics/ftk-imager-lite-version-3.1.1" rel="nofollow noopener">FTK imager</a> or <a href="http://www.magnetforensics.com/magnet-acquire/" rel="nofollow noopener">Magnet Aquire</a>. Output the full physical disk to your destination disk. Be sure to make continuous notes of what you are doing, videos, pictures of the system and be sure to check the image has been MD5 verified by the hash sum, then you can be sure the copy is identical to the original.</p>
<h3><strong>Forensic Imaging Using a Forensic Bootdisk or USB</strong></h3>
<p>Using a bootdisk is the preferred method as you don&#8217;t need to waste time opening up a drive. The operating system uses the system as a terminal device, and the hard disks are by default blocked. This method works on most Macs, Windows and Linux systems.</p>
<h3><strong>Caine, Paladin &amp; Deft &#8211; 3 Free Computer Forensic Bootable Linux Distros</strong></h3>
<p>Firstly download a distro, my favourite is favourite is <a href="http://www.google.co.uk/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=1&amp;cad=rja&amp;uact=8&amp;ved=0ahUKEwiR8enrkKPPAhVjCcAKHeXcA_UQFggeMAA&amp;url=http%3A%2F%2Fwww.caine-live.net%2F&amp;usg=AFQjCNES4stuj9bYhjYNBZM6k7Ydz7Jjpg&amp;sig2=jKaTTxJVWfQuCrQ0pfR7MQ" rel="nofollow noopener">Caine</a>. Famous actor Michael Caine assembles it (Only kidding it is made by Italian consultant <a href="http://www.nannibassetti.com/" rel="nofollow noopener">Nanni Bassetti</a>!). Another great free distro that you have to register to obtain is <a href="http://sumuri.com/" rel="nofollow noopener">Suri&#8217;s Paladin</a>, see <strong>Fig 4</strong>. Download the ISO from the <a href="http://www.caine-live.net/" rel="nofollow noopener">website</a> then burn the ISO to a DVD or use <a href="http://rufus.akeo.ie/" rel="nofollow noopener">Rufus</a> with default settings to make a bootable USB disk. To produce a bootable USB in Rufus merely select the USB stick, click the disk logo and locate the ISO you just downloaded then hit the start button and wait for your bootable USB to be prepared. Always have a copy of <a href="http://www.deftlinux.net/" rel="nofollow noopener">DEFT</a> or <a href="http://e-fenseinc.sharefile.com/share?#/getinfo/sda4309a624d48b88" rel="nofollow noopener">Helix</a>handy on a compact disk rather than DVD in case you are working on a device that won&#8217;t boot from DVD or USB. from a device that won&#8217;t boot from DVD or USB.</p>
<h3>Fig 4 Paladin&#8217;s ToolBox Imaging Graphical User Interface in Linux Running in Live Mode on a Host Machine</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C4E12AQEYega-cd7JKQ/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4oBywWAL1yiAPQzAKEiA3snMu77Bt9H-vsN_GIcs0pk" width="744" data-media-urn="urn:li:digitalmediaAsset:C4E12AQEYega-cd7JKQ" data-li-src="https://media.licdn.com/dms/image/C4E12AQEYega-cd7JKQ/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4oBywWAL1yiAPQzAKEiA3snMu77Bt9H-vsN_GIcs0pk" /></p>
<p><strong>Booting Your Computer Forensics Distribution in the Bios</strong></p>
<p>Before any booting of the system from a switched off state do some research into what key combinations trigger the boot disk. It varies, on a Mac hold the &#8216;Option Key&#8217; or &#8216;C&#8217;, on a Windows system it could be anything from &#8216;F1&#8217; or &#8216;Del&#8217;. Take time to look through <a href="http://craftedflash.com/info/how-boot-computer-from-usb-flash-drive" rel="nofollow noopener">this </a>list before switching to the system in preparation for booting into a Forensic OS. If you get it wrong, you may boot into the operating system if this event occurs switch the computer off by the button (if safe) or pull out the power cord.</p>
<p>Then the general idea is to use a GUI program such a Guymager as shown in <strong>Fig 5 </strong>to acquire the media to the destination drive without removing the disk while preserving the integrity of the drive. You need to remember to unlock your destination drive.</p>
<p><strong>Fig 5 Guymager Forensically Imaging 2 Attached Disks USB Disk</strong></p>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQEtca7bnr82rw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=BbjwN4lWg0i155NrJos2y3jQbkTCX3EhoEL3yl_nSPw" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQEtca7bnr82rw" data-li-src="https://media.licdn.com/dms/image/C5612AQEtca7bnr82rw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=BbjwN4lWg0i155NrJos2y3jQbkTCX3EhoEL3yl_nSPw" /></p>
<h3><strong>Remote Forensic Imaging over a Network</strong></h3>
<p>A computer forensic examiner would place a clean virus free computer on the network and attach to the companies domain. Using Encase Enterprise or FTK v5.6+ a computer forensic examiner, with root access, could push an agent to gain access to a remote system. The RAM could be examined for malware and Physical Disk in Read-Only mode. The examiner could then review the computer in real time to produce a logical forensic skeleton image of only the files that are of interest. Alternatively, the examiner could copy the disk remotely and have it outputted to a secure location on the server or locally.</p>
<p>If the user profile exists on the server, it might be sufficient to mount the remote disk or user share in logically in Windows by selecting &#8216;Map Network Drive&#8217; and using FTK Imager to image the contents locally logically. The local machine should be physically copied where possible in addition to the remote user directory for completeness.</p>
<h3><strong>Forensic Imaging Mobile Phones &#8211; iOS, Blackberry, Windows and Android</strong></h3>
<p>If you come across a phone place it in aeroplane mode or switch it off immediately as it is easy to wipe a device remotely using iCloud&#8217;s &#8216;Find My Phone&#8217; or Similar apps of that ilk.</p>
<p>For a mobile phone forensics expert Magnet&#8217;s free software Aquire, CellBrite, UFED and XRY can be used to grab an image logically and physically of a mobile device. A logical grab will obtain the filesystem and no deleted data (except items in the SQL databases that can be logically recovered and scraped from these databases).</p>
<p>A physical &#8216;Hex Dump&#8217; of a mobile device is the holy grail of mobile acquisition. Hex dumping entails the device to be rooted or jailbroken as so a 3rd party app can exploit the phone allowing the device to be imaged much like a computer hard drive. From this image, deleted data can is gathered.</p>
<h3>Mobile Phone Backups</h3>
<p>It is also worth a mention that Mobilebackups in the form of BBB/IPD Blackberry backups and Mobilesync backups for Apple may exist on the computer system seized that can be read much like actual mobile device if for some reason the device is no longer available. These backups may contain messages, photos and chat conversations.</p>
<p>Thank you for reading my overview of forensic imaging. I hope it was informative.</p>
<p>By Alistair Ewing Director of Compute Forensics</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Create a Forensic Windows Based OS for Free for Forensic Imaging and Triage</title>
		<link>https://compute-forensics.com/how-to-create-a-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Mon, 04 Jun 2018 12:29:56 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Data Acquisition]]></category>
		<category><![CDATA[Forensic Imaging]]></category>
		<category><![CDATA[Triage]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1776</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">How to Create a Forensic Windows Based OS for Free for Forensic Imaging and Triage</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				04/06/2018			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Software, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/how-to-create-a-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img fetchpriority="high" decoding="async" width="1030" height="550" src="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-1030x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1530194840588" >
		<div class="wpb_wrapper">
			<h3>Introduction</h3>
<p>This brief overview is designed for those with an IT background, students, forensic analysts or budding first responders.  This will teach you the basics of how to create a Windows-based forensic OS for imaging and less commonly triage for free provided you own a valid Windows licence.</p>
<p>The consultancy <strong>Compute Forensics</strong> offers a worldwide three-day onsite first responder training in English and the Thai language for corporates, military and international police services. Those who have moderate computer literacy can be trained to triage and collect without affecting the original medium before handing over to a computer forensic expert or even the authorities. One should never start using self-made tools without testing.</p>
<p><a href="https://compute-forensics.com/contact-us/" rel="noopener">Contact us</a> for a quote in regards to training, collection or even an investigation.</p>
<p>We also offer a remote triage service, by sending a bootable drive with secure remote access software pre-installed we can forensically image a device from across the world without modifying the contents thus preserving the material.</p>
<p>I recommend the online training and exam from the forensic author, Brett Shavers. He runs an online course which you can find <a href="http://courses.dfironlinetraining.com/forensic-operating-systems?pc=fos-032018">here</a>.</p>
<p>Please be mindful this guide is for research purposes. Please test and <strong>use at your own risk! </strong></p>
<p>Be mindful that specific software may be not allowed for use in corporate settings as you may break the software companies EULA agreement.</p>
<h3>How Does a Forensic Windows OS Work?</h3>
<p>If the build process completes correctly, a unique modified Windows is created on a USB drive, ISO or CD or DVD. When booting from a forensic OS, the BIOS of the host system bypasses the internal physical disk booting from the information on the USB drive (for Windows To Go) or the data saved to the volatile RAM transferred from the boot media (for Mini-WinFE.)</p>
<p>Windows should not mount the internal fixed disk but connected USB disks in the case of Windows To Go or any discs what so ever using WinFE.</p>
<p>Please note: When using <strong>DISKPART </strong>from CMD in Windows To Go you can mount Disks Read Only but NOT Volumes. Doing so writes to the disk. You can still image using Forensics or FTK Imager without doing any mounting. If you want to use specific triage tools in a blocked mounted state, you may need to bring the disk online, but remember never bring the Volume online. <strong>ALWAYS</strong> test your build.</p>
<p>Practice using Diskpart and the toggling of online and offline correct, many think they are smart using the command line, but one wrong move and you could wipe, format or mount a volume leaving you to explain your actions in an Expert Witness or corporate hearing.</p>
<h3><strong>Why Would I Need a Windows Based Forensic OS?</strong></h3>
<p>Other forensic OS’s exist as do physical writeblockers. <strong>Linux</strong> (<a href="https://www.caine-live.net">Caine</a>, <a href="https://sumuri.com/software/paladin/">Paladin</a>, and others) and <strong>Mac</strong> formats (Sumuri’s <a href="https://sumuri.com/software/recon/">Recon</a> &amp; BlackBag’s <a href="https://www.blackbagtech.com/software-products/macquisition.html">Macaquisition</a>) can collect data, but I estimate 80% of forensic software is produced for Windows. Imagine being able to boot into Windows and use tools such as Netcat, FTK Imager, <a href="https://www.osforensics.com">OSforensics</a> or even full-blown FTK on your Bitlockered Frankenstein creation. This would enable you to carry a Swiss army knife of tools at your disposal.</p>
<p>Using a <strong>Windows Forensic OS</strong> you can:</p>
<ul>
<li>Collect data from software RAIDS and logically image the device rather than having to piece together physical images later saving time.</li>
<li>Decrypt Bitlockereddrives and image/triage them in a decrypted state and physical state consecutively using CMD looking something like “manage-bde –unlock E: -recoverypassword 111111-222222-333333-444444-555555-666666-777777-888888.”</li>
<li>Produce decrypted logical images on the fly from Truecrypt, PGP and Veracrypt using default Windows tools.</li>
<li>Boot into your Bitlockered ‘Windows To Go’<strong> </strong>and use your client’s hardware to attach to their domain with admin rights temporarily, run FTK to capture a suspects RAM and physical disk Image remotely without having to lug a laptop or even worse a workstation to the client’s site.</li>
<li>Travel light with a few USB keys in different countries without lugging 20 pelican cases and getting stopped by airport security whom mistake the devices for dirty nuclear bombs.</li>
<li>Use data recovery tools such as photorec without making changes to the drive.</li>
<li>Triage and quickly find and capture forensically the information needed with only primary first responder training and no expensive equipment.</li>
<li>Production of a log2timeline to capture users actions between specific dates.</li>
<li>Windows2go could be sent to a client with a copy of Teamviewer or similar. With instructions and connected to the internet the client could boot into the forensic OS, an examiner from across the world can log in and take over the collection process going on to capturing the internal physical disk as an E01 to an encrypted drive. When complete the client can mail the item back for analysis saving on travel costs.</li>
</ul>
<h3>Forensic OS Route 1: Native to Enterprise ‘Windows To Go’</h3>
<p>If you own a copy of Windows 10 Enterprise and you purchase one of the certified ‘Windows To Go’ drives (See Below) to make your OS. All you need to do is press the “Win Key&amp; Q” together and type ‘Windows To Go’ into the search bar. Plug in your drive and follow the instructions. You will be asked if you want to Bitlocker the drive, it is recommended but be aware it may not boot on Mac’s or specific other systems.</p>
<p><strong>Certified Windowstogo Drives</strong></p>
<ul>
<li>Imation IronKey™ Workspace W300 / W500 / W700</li>
<li>Kingston DataTraveler Workspace</li>
<li>Spyrus Portable Workplace</li>
<li>Spyrus Secure Portable Workplace</li>
<li>Spyrus WorkSafe</li>
<li>Super Talent RC4 / RC8</li>
<li>WD My Passport Enterprise</li>
<li>SanDisk Extreme CZ80 USB 3.0 Flash Drive</li>
<li>SanDisk Extreme CZ88 USB 3.0 Flash Drive</li>
</ul>
<h3>Using Other Drives Including an M.2 SSD in a USB 3.1 Caddy</h3>
<p>If you are a ‘Cheap Charlie’ or are feeling more adventurous, you can try other disks, although they are unsupported officially.</p>
<p>I tested a “SAMSUNG M.2 NGFF 128GB SSD SOLID STATE DRIVE MZ-NTE1280” (£40 from Amazon) inside a USB 3.1 “Type C To M.2 NGFF PCI-E SSD Hard Disk Case Enclosure 2242/2260/2280 caddy” (£10 pictured below.) When the enclosure arrived in the post, it looked like something out of a Christmas cracker. When I assembled the device, which took two minutes, I was pleased with how robust it felt. Windows To Go recognised the disk. Windows To Go was installed in about 10 minutes using the built-in GUI.</p>
<p>Speeds faster than the ‘certified’ drives were noted in tests at around 500mb a second read/write and use was not noticeably slower than using my native Crucial M.2 built into my high-end test laptop.</p>
<p><img decoding="async" class="size-full wp-image-1182 aligncenter" src="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?resize=485%2C393&amp;ssl=1" alt="Make your own bootable Windows for travel" width="483" height="391" data-attachment-id="1182" data-permalink="https://compute-forensics.com/how-to-create-forensic-windows-based-os-for-free-for-forensic-imaging-and-triage/bespoke_windows-yo-go_caddy/" data-orig-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=485%2C393&amp;ssl=1" data-orig-size="485,393" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Cyberdyne&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1521662693&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="Bespoke_Windows-to-go_Caddy" data-image-description="" data-medium-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=300%2C243&amp;ssl=1" data-large-file="https://i2.wp.com/compute-forensics.com/wp-content/uploads/2018/03/Bespoke_Windows-yo-go_Caddy.jpg?fit=485%2C393&amp;ssl=1" /></p>
<p>To use the newly created OS on a stick, you need to plug it into a computer and press whatever button you need to boot from your disk, not the internal drive (Esc, F11, F12, Delete.) On first boot, you will have to setup Windows just like any other new installation of Windows. Do not wait until you are on the client site!</p>
<h3>Using DISKPART to Bring Disks Online</h3>
<p>When you use Windows To Go any attached USB devices will be writable. The internal disks will be offline and unavailable to Windows. FTK Imager and other software will still be able to view, image and parse the internal drives. If you wish to Triage using other tools you may need to bring the disk online using disk manager or DISKPART in CMD as an admin. The command would be something like:</p>
<p>1) Run CMD as an admin</p>
<p>2) Type DISKPART</p>
<p>3) LIST DISKS</p>
<p>4) SELECT DISK 2 (2 being an example of the internal disk under review)</p>
<p>5) ONLINE DISK. The disk should then be shown in explorer but in a blocked state. Practice taking the disks offline and online using DISKPART before using this on evidence! You should be able to use Nirsoft and other live tools to analyse the internal disk without writing to it.</p>
<p><img decoding="async" class="aligncenter" src="https://i1.wp.com/support.ca.com/cadocs/0/CA%20ARCserve%20Replication%20and%20High%20Availability%20r16%205-ENU/Bookshelf_Files/HTML/VMS/2069447.png?w=1140&amp;ssl=1" alt="list disk and volume command" width="534" height="181" /></p>
<p>It is noteworthy to mention boot USB producing software Rufus produces Windows To Go but this has not been tested yet!</p>
<p>The downside to this method is that you need to learn the command prompt of DISKPART, this isn’t easy but not ideal for first responders. People with less Windows knowledge and whom want a cleaner smaller build should consider building a custom Mini-WinFE.</p>
<h3>Forensic OS Route 2: Building your Own Custom Mini-WinFE</h3>
<p>Using a GUI assembler and Windows installation media, it is possible to build a bootable OS in minutes that will have a GUI disk read/write toggler, can contain tools such as FTK Imager or DD and be under 300mb in size. This is enough to fit onto a writable CD or Mini CD (recommended for compatibility even old systems have CD drives) or even a dated 1.0 or 2.0 USB key.</p>
<p>The beauty of that is you can customise a stripped down version of Windows that can triage, is blocked using a GUI and that boots in seconds without all the ‘fluff’ the Windows To Go build contains.</p>
<p>Producing a Mini-WinFE is tricky, and if you add too many features you may end up bypassing the protection making the internal disks prone to changes, not good!</p>
<p>The secret is not to add too many features and test your creation on your system, not evidence.</p>
<p>Below is a step by step how-to produce your first basic 32-bit Forensic Mini-WinFE:</p>
<p><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-1781" src="https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-300x241.jpg" alt="" width="600" height="481" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-300x241.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-768x616.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE-600x481.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/PE-Bakery_Build-Mini_WINFE.jpg 883w" sizes="auto, (max-width: 600px) 100vw, 600px" />(Above) Mini-WinFE’s GUI </strong></p>
<ol>
<li>Download Mini-WinFE <a href="http://www.brettshavers.cc/index.php/brettsblog/entry/windows-forensic-environment-newest-project-is-complete">here</a> or <a href="https://ln.sync.com/dl/62e6302b0#r8in7m6s-xydgcwp9-hb2dbfg9-ijybm5rm">here.</a></li>
<li>Extract the Zip to a clean directory and run the launcher inside the Mini-WinFE folder as an admin.</li>
<li>Mount your Windows installation ISO or slip the DVD into your disk drive. I prefer 32-bit as it boots on both types of system. I used Windows 10 Enterprise as the Windows build.</li>
<li>In settings point your source directory to your Windows DVD location or the folder you have dumped the contents of the Windows installation media.</li>
<li>Create a working directory in the Mini-WinFE folder you just extracted and use this as your target directory.</li>
<li>Go to the FTK imager tab and point FTK to any 32-bit EXE. You can register and download Imager from <a href="https://accessdata.com/product-download">here</a>. I like to use version 3.1.1. A 64-bit version cannot be built into the cache for a 32-bit machine.</li>
<li>In the ‘Path to 32-bit’ area press the folder button and select the FTK image EXE file you have installed or extracted.</li>
<li>Option 1 allows you to select booting from FLAT or RAM. I would choose RAM; FLAT means the item boots from the medium and results in a larger ISO or USB output.</li>
<li>Tick all the programs boxes except add custom batch and folders unless you wish to do this.</li>
<li>Tick the create ISO tab and read the hover over suggestions.</li>
<li>In the create ISO section option 3 the drop-down box allows a user to select the Firmware type. Older computers use BIOS (Basic Input Output System) newer have UFEI firmware and can ofter boot the older BIOS software or UFEI. There are three options; I would select the ‘both’ option if you are unsure.</li>
<li>Select ‘oscdimg’ for an option.</li>
<li>Change the optimise option to ‘yes’ for option 5. This will result in a smaller ISO.</li>
<li>Selecting ‘yes’ for option 6 will build the ISO file in a newly created \mistyPR.Project.Output folder path in your project folder. Selecting ‘no’ will name the iso with the date and time to allow you to make multiple builds without writing over the older builds.</li>
<li>Select the triangular ‘Play’ logo with the ‘Build’ tab underneath.</li>
<li>If all goes well, you should have built your first forensic ISO. The file can be found in the output folder of your Mini-WinFE folder or the root of that folder.</li>
<li>The ISO can be burnt to CD, Mini-CD or DVD, or you can also use <a href="https://unetbootin.github.io">Unetbootin</a> or <a href="https://rufus.akeo.ie">Rufus</a> to make a bootable USB from the ISO.</li>
<li>Sometimes a system won’t boot from a USB or not from sometimes a CD or DVD. Produce a few versions and label them.</li>
<li>You will have to tinker to get different builds to boot on different systems. To work on my system, I had to enter the BIOS, change the boot from UFEI to legacy. Be careful on evidence that has a TPM chip linked BitLocker as you could end up rendering the drive unbootable by disabling TMP in the BIOS.</li>
<li>Be sure to photograph the Bios when working with real evidence. In the boot setup of the BIOS take all the internal disks offline and have your forensic USB followed by CD/DVD in the boot order.</li>
<li>If the process works, you will be greeted by the disk manager, and this shows you which disks you can make writable or bring online for triage. <strong>Be careful not to bring the evidence volumes online.</strong> You can right click to find out more about the disk to make sure you make the correct selection. You don’t need to bring a disk online to image it though.</li>
<li>Closing the file manager window results in a forensic desktop being displayed.</li>
<li>Right-clicking on the desktop displays the drop-down menu in which you can scroll through and make utilisation of the differing tools.</li>
<li>Below displays a screenshot of the ISO successfully running in a test virtual box environment.</li>
</ol>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-1782" src="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-300x246.jpg" alt="" width="600" height="492" srcset="https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-300x246.jpg 300w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-768x629.jpg 768w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-1024x839.jpg 1024w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows-600x492.jpg 600w, https://compute-forensics.com/wp-content/uploads/2018/06/Mini-WinFE_Running-from-32-Bit-Windows.jpg 1030w" sizes="auto, (max-width: 600px) 100vw, 600px" />Please Like or Share this guide should you find it useful!</p>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1530552651544 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Looking for a Remote Collection or Investigation Service?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Global Forensic Imaging Service</title>
		<link>https://compute-forensics.com/computer-forensic-imaging/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Fri, 22 Jan 2016 05:43:23 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Data Acquisition]]></category>
		<category><![CDATA[Forensic Imaging]]></category>
		<guid isPermaLink="false">http://consulting.stylemixthemes.com/?p=748</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid vc_custom_1459507906849"><div class="wpb_column vc_column_container vc_col-sm-12 vc_col-lg-9 vc_col-md-9"><div class="vc_column-inner vc_custom_1452702342137"><div class="wpb_wrapper"><div class="vc_custom_heading no_stripe text_align_left" ><h2 style="color: #111111;text-align: left" class="consulting-custom-title">Global Forensic Imaging Service</h2></div><div class="post_details_wr ">
    
<div class="stm_post_info">
	<div class="stm_post_details clearfix">
		<ul class="clearfix">
			<li class="post_date">
				<i class="fa fa fa-clock-o"></i>
				22/01/2016			</li>
			<li class="post_by">Posted by:				<span>Alistair Ewing</span>
			</li>
			<li class="post_cat">Categories:				<span>Computer Forensics, Investigative Techniques, Legal, Uncategorized</span>
			</li>
		</ul>
		<div class="comments_num">
			<a href="https://compute-forensics.com/computer-forensic-imaging/#respond"><i class="fa fa-comment-o"></i>No Comments </a>
		</div>
	</div>
			<div class="post_thumbnail">
			<img loading="lazy" decoding="async" width="768" height="550" src="https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-768x550.jpg" class="attachment-consulting-image-1110x550-croped size-consulting-image-1110x550-croped wp-post-image" alt="" srcset="https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-768x550.jpg 768w, https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-350x250.jpg 350w, https://compute-forensics.com/wp-content/uploads/2016/01/2011-07-13-09-54-24-255x182.jpg 255w" sizes="auto, (max-width: 768px) 100vw, 768px" />		</div>
	</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1530092935130" >
		<div class="wpb_wrapper">
			<p><strong>Compute Forensics LTD</strong> offer a global reach for our personalised forensic imaging process. We have agents and associates available at short notice to collect a plethora of data forensically. We cater to law firms, litigation support and even provide services for other digital forensic companies!</p>
<h4>Why perform a forensic acquisition? Why not just copy the data?</h4>
<p>Using IT staff or a layperson to copy data for a legal case or tribunal may jeopardise the integrity of the source data. Files are volatile, and any access or removal may result in data loss, a change in time stamp records or inadmissible evidence. Using a Compute Forensics LTD vetted Digital Forensic Expert ensures that the data can be copied in its entirety where possible including deleted areas and other partitions not picked up by copying. Along with that full chain of custody logs, exhibit tracking, digital fingerprints and collection reports can be produced to your companies or international standards. The end product will be working, and a backup copy of the target disk be it a Windows Machine, Apple Mac, Linux server or mobile phone (4000+ models supported) and documentation above. The deliverables can then be examined and exhibited. The exhibits and documents must appear robust enough to stand the scrutiny of the worlds most vigilant expert witnesses. The main advantage of examing a forensic image over the source disk is that exploring, even in a blocked state, may wear the source storage unit thus rendering any chance of precious data recovery and investigation impossible.</p>

		</div>
	</div>
<div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1452700243026"><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<ul>
<li style="margin-bottom: 15px;"><strong>Tools and techniques</strong><br />
<span style="font-size: 13px;">Compute Forensics use a parallel forensic imaging approach, so the client only billed for the hour. The method the collection expert uses mean that specialist can copy as many drives at once as there are power sources. We image using tested forensic boot USB disks, and the fastest USB 3.0-3.1 write blocking equipment only.</span></li>
<li style="margin-bottom: 15px;"><strong>Remote Imaging</strong><br />
<span style="font-size: 13px;">On occasions, it may not be possible for an examiner to go the location of the data in person. In these circumstances, Compute can mail out a custom USB disk or CD and an encrypted destination USB 3.0 external drive. Compute can carefully guide the client through booting up the forensic write-blocked operating system. The user establishes a secure remote connection through the internet, and the expert can then go on to set the target disk copying to the now unencrypted destination drive. On completion the client can unplug the destination disk, sending it tracked to the processing lab preferred location. Should the destination data drive become lost in the postal system the client’s intellectual property is safe as the entire drive is locked using Veracrypt or similar needing a password to view the contents.</span></li>
</ul>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-6"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<ul>
<li style="margin-bottom: 15px;"><strong>What happens when you come across Faulty Disks?</strong><br />
<span style="font-size: 13px;">We do not except filling in data with zeros on faulty sectors where evidence may reside or retrying defective drives further damaging the disk. Using advanced data recovery tools can copy the whole disc and retry bad areas until we get as close to a full 100% read as possible.</span></li>
<li style="margin-bottom: 15px;"><strong>We have a server or system that cannot be powered down, can you still aid us?</strong><br />
<span style="font-size: 13px;">Yes! By using special forensic software and techniques, our digital collection specialists can copy live files that are in use while preserving the Last Modified dates and other relevant metadata.</span></li>
</ul>
<p>Once all the data has completed copying over and verifying, the files are then to be packaged inside a forensic container file. Unique digital fingerprints as MD5 or SHA1 hash sums are generated and certified identical to the original to ensure data integrity before signing the data out.</p>
<p>There is no need for server downtime!</p>

		</div>
	</div>
</div></div></div></div></div></div></div><div class="wpb_column vc_column_container vc_col-sm-3 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner "><div class="wpb_wrapper">
<div class="stm_sidebar">

            <style type="text/css" scoped>
            .vc_custom_1452056597103{margin-right: 0px !important;margin-bottom: 30px !important;margin-left: 0px !important;}.vc_custom_1451998133493{margin-bottom: 30px !important;}.vc_custom_1452056633692{padding-top: 37px !important;padding-right: 30px !important;padding-bottom: 40px !important;padding-left: 30px !important;}.vc_custom_1527964913946{margin-bottom: 9px !important;}.vc_custom_1527964962623{margin-bottom: 17px !important;}.vc_custom_1527965000155{margin-bottom: 30px !important;}        </style>
        <div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1452056597103"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner vc_custom_1452056633692"><div class="wpb_wrapper"><div class="vc_custom_heading vc_custom_1527964913946 text_align_left" ><div style="font-size: 16px;color: #222222;text-align: left;font-family:Poppins;font-weight:600;font-style:normal" class="consulting-custom-title">Contact Us</div></div>
	<div class="wpb_text_column wpb_content_element vc_custom_1527964962623" >
		<div class="wpb_wrapper">
			<p><span style="font-size: 13px; line-height: 22px;">Compute Forensics are based in London but are available for contracts and work in the global area. Please don’t hesitate to email us at expert@compute-forensics.com for a free online or call consultation.</span></p>

		</div>
	</div>
<div class="vc_btn3-container vc_btn3-inline vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-sm vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-left vc_btn3-color-white" href="https://compute-forensics.com/contact-us/" title=""><i class="vc_btn3-icon fa fa-phone-square"></i> contacts</a></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1451998133493"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper"><div class="vc_btn3-container vc_btn3-left vc_custom_1527965000155 vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-lg vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-block vc_btn3-icon-left vc_btn3-color-theme_style_1" href="https://compute-forensics.com/pdf/" title="" target="_blank"><i class="vc_btn3-icon fa fa-file-pdf-o"></i> Computer Forensics Professional Services PDF</a></div></div></div></div></div>
</div>    
</div></div></div></div></div><div data-vc-full-width="true" data-vc-full-width-init="false" class="vc_row wpb_row vc_row-fluid third_bg_color vc_custom_1459505959648"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
<section class="vc_cta3-container" >
    <div class="vc_general vc_cta3 third_bg_color vc_cta3-style-flat vc_cta3-shape-square vc_cta3-align-left vc_cta3-color-classic vc_cta3-icon-size-md vc_cta3-actions-right vc_custom_1527966594214 style=""">
                        <div class="vc_cta3_content-container">
                                    <div class="vc_cta3-content">
                <header class="vc_cta3-content-header">
                    <div class="vc_custom_heading" ><h2 style="font-size: 20px;color: #ffffff;line-height: 24px" class="consulting-custom-title">Are you looking for a Compute Forensic Consultant?</h2></div>                                    </header>
                            </div>
                        <div class="vc_cta3-actions"><div class="vc_btn3-container vc_btn3-right vc_do_btn" ><a class="vc_general vc_btn3 vc_btn3-size-md vc_btn3-shape-rounded vc_btn3-style-flat vc_btn3-icon-right vc_btn3-color-theme_style_2" href="https://compute-forensics.com/contact-us/" title="">get a quote <i class="vc_btn3-icon fa fa-chevron-right"></i></a></div></div>        </div>
                    </div>
</section></div></div></div></div><div class="vc_row-full-width vc_clearfix"></div>
</div>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
