<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Collection Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<atom:link href="https://compute-forensics.com/tag/data-collection/feed/" rel="self" type="application/rss+xml" />
	<link>https://compute-forensics.com/tag/data-collection/</link>
	<description></description>
	<lastBuildDate>Thu, 28 Jun 2018 18:13:51 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://compute-forensics.com/wp-content/uploads/2018/06/cropped-cropped-CF-1-32x32.png</url>
	<title>Data Collection Archives - Compute Forensics LTD London Computer &amp; Mobile Phone Forensic Expert Witness Investigation Services</title>
	<link>https://compute-forensics.com/tag/data-collection/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What is Imaging in Computer Forensics and E-Discovery?</title>
		<link>https://compute-forensics.com/what-is-computer-forensic-imaging/</link>
		
		<dc:creator><![CDATA[Alistair Ewing]]></dc:creator>
		<pubDate>Thu, 28 Jun 2018 18:13:51 +0000</pubDate>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Data Acquisition]]></category>
		<category><![CDATA[Data Collection]]></category>
		<category><![CDATA[Forensic Imaging]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Physical Image]]></category>
		<category><![CDATA[Targeted Collection]]></category>
		<guid isPermaLink="false">https://compute-forensics.com/?p=1827</guid>

					<description><![CDATA[DISCLAIMER Only a qualified computer forensics expert from a company such as Compute Forensics should be selected to perform forensic data collection. You can call us on +44 (0)203 5989658, email us at expert@compute-forensics.com or &#8216;Live Chat&#8217; to a computer forensics expert witness by clicking on the red tab at the left of the website. Compute Forensics offers a global collection service]]></description>
										<content:encoded><![CDATA[<h3>DISCLAIMER</h3>
<p>Only a qualified computer forensics expert from a company such as Compute Forensics should be selected to perform forensic data collection. You can call us on +44 (0)203 5989658, email us at <a href="http://mailto%40expert@compute-forensics.com/" rel="nofollow noopener">expert@compute-forensics.com</a> or &#8216;Live Chat&#8217; to a <a href="http://compute-forensics.com/?portfolio=computer-forensics" rel="nofollow noopener">computer forensics expert witness </a>by clicking on the red tab at the left of the website. Compute Forensics offers a global collection service for e-Discovery firms, Digital Forensic firms and businesses under litigation. <a href="http://compute-forensics.com/contact-us/" rel="nofollow noopener">Compute Forensics</a> can provide training and equipment to IT departments that require the collection skills themselves as to give a lightning response that is needed when the need arises.</p>
<h3>Introduction</h3>
<p>This article is designed to be a general overview of the actions, programs and techniques used in data collection before scenarios such as a digital investigation of a recently departed employee or for an <a href="http://compute-forensics.com/?portfolio=email-discovery" rel="nofollow noopener">e-Discovery</a> litigation hold.</p>
<h3>What is Forensic Imaging?</h3>
<p>Forensic imaging, in a nutshell, is the act of gathering data in a court accepted fashion from digital media to a <a href="http://veracrypt.codeplex.com/" rel="nofollow noopener">Veracrypted</a> encrypted output device where possible. That data may come from a live system, a dead PC, DVD, iMac, USB disk, X-Box or remote mailbox. Those are just a few examples.</p>
<p>Typically, the source media should be placed into a blocked state when being read and the data outputted to an attached destination disk with read/write access. It is essential contiguous notes of the system and steps taken are made while the imaging is taking place. The forensic imaging should be done by a certified, experienced <a href="http://www.linkedin.com/in/computerforensicsexpertwitness" rel="noopener">digital forensics expert witness</a> or at least an individual with collection training and IT knowledge.</p>
<p>On certain occasions blocking writes to the source media may not be possible such as if you are presented with a live system server or an encrypted system that is discovered switched on. In these instances, the image must be taken live as not to disturb a server or re-encrypt an unlocked disk.</p>
<p>In addition to noting the collection process, it is important to note the physical location of the evidence and store it in a compliant manner and always gain signatures when handing over data.</p>
<p><strong>Tip: </strong>As a rule, if the system is switched off leave it that way. If it is changed on leave, it switched on but take the computer, laptop or phone off the network and connected to power. For a computer that may mean unplugging the network cable, sliding a switch to ensure WIFI is off, pulling out a dongle, popping out a network card or disabling networking in the control panel of the operating system. For a tower computer, it may mean just pulling out the Ethernet cable.</p>
<h3>What is a Physical Forensic Image?</h3>
<p>A physical forensic image is a full &#8216;bit for bit&#8217; copy of the particular media. This includes every byte of data from the live file system to the unallocated deleted areas of the disk.</p>
<p>The forensic image may be outputted in some formats such as a simple format agnostic raw dd image format, the common EnCase E01 evidence image or the less common Advanced Forensics Format (AFF). If you wrote this forensic image back to a disk in its raw format (FTK has this functionality) with the same capacity, it would be identical in every way to the original. From this image, a computer forensic analysis would be conducted as not to risk damaging the original.</p>
<p>I have personally experienced occasions where forensic software wasn&#8217;t used to collect the data for some reasons like a RAID wasn&#8217;t being recognised on older systems or the disk was not being read in Windows. In these instances, something akin to a bootable <a href="http://clonezilla.org/clonezilla-live.php" rel="nofollow noopener">Clonezilla Live</a> distro may be used to produce the image. When doing so always explain your reasoning in notes and find the verify or MD5 hash the result if necessary. Getting something is better than walking away with no data at all. Again this should always be done by a qualified person that is well versed in <a href="http://compute-forensics.com/" rel="nofollow noopener">forensic imaging</a>.</p>
<h3>What is a Logical Forensic Image?</h3>
<p>A logical forensic image or skeleton image is a particular copy of certain files from a source. Many programs can produce logical images: Stefan Fleischmann&#8217;s excellent <a href="http://www.x-ways.net/imager/" rel="nofollow noopener">X-Way&#8217;s Imager</a>, the superb and free <a href="http://accessdata.com/product-download/digital-forensics/ftk-imager-lite-version-3.1.1" rel="nofollow noopener">FTK Imager</a> or new on the scene <a href="http://www.magnetforensics.com/acquire-community/" rel="nofollow noopener">Magnet&#8217;s Acquire software</a> can be used to do this in a Windows environment.</p>
<p>A logical acquisition is the option to use if the digital expert requires a targeted collection for litigation reasons, just a few files of interest are needed, or the client collect wishes you to collect from one or more custodian&#8217;s user profiles from a server that may have many users.</p>
<p>In an active state, <a href="http://marketing.accessdata.com/ftkimagerlite3.1.1" rel="nofollow noopener">FTK Imager Lite</a> as shown in <strong>Fig 1, </strong>can be executed from the destination disk on the computer you wish to extract from as not to write to the live computer by installing software to the source. A custom content list can be built into the programs user interface, and a logical forensic image file is thus produced.</p>
<p>FTK Imager can be used to mount forensic images to view in Windows Explorer, build custom content images of live machines, image RAM (random access memory) from a live system, view and export from Linux/Mac/Windows filesystems and most commonly forensically image a hardware or software writeblocked device to an external disk. FTK Imagers only drawback is when an examiner images a damaged disc the software fills in the unreadable sectors with 0&#8217;s. Not attempting to read the drive is unacceptable when a data recovery solution such as &#8216;<a href="http://www.gnu.org/software/ddrescue/" rel="nofollow noopener">ddrescue</a>&#8216; may recover a whole email collection where the forensic tool fills what it can&#8217;t read with 0&#8217;s. In an investigation or legal hold, every byte counts! I have been the examiner that has acquired 100% of an image where others had to explain in court why some sectors weren&#8217;t imaged.</p>
<h3>Fig 1 FTK Imager Version 3.3.0.5 the Crème De La Crème of Forensic Imaging Tools</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C4E12AQF1Hr2Ve6VlGw/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=OT-y1xyC4elrOewQLkMfpVUchbPEDIYvFtv-oZ3PdP4" width="744" data-media-urn="urn:li:digitalmediaAsset:C4E12AQF1Hr2Ve6VlGw" data-li-src="https://media.licdn.com/dms/image/C4E12AQF1Hr2Ve6VlGw/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=OT-y1xyC4elrOewQLkMfpVUchbPEDIYvFtv-oZ3PdP4" /></p>
<p>On a live Mac you may want to produce a full image using a bootable Linux forensics distribution such as <a href="http://www.caine-live.net/" rel="nofollow noopener">Caine </a>then go on to build a list from that main image onsite should the client not want all the data walking off site. There are other solutions like BlackBag&#8217;s convenient <a href="http://www.blackbagtech.com/software-products/macquisition.html" rel="nofollow noopener">MacQuisition</a>.</p>
<h3>Verification MD5 and SHA1</h3>
<p>The verification information is hardcoded inside the metadata of the image in the case of most advanced forensic image formats such as E01, AD1, and AFF. A log is produced by any decent imaging software with a verification sum generated for the forensic image to signify the image is identical to the original. Verification is done so that the professional examining the image can be sure the image hasn&#8217;t changed since it was taken by checking the MD5 or SHA1 hash sum or other before commencing the investigation.</p>
<p><strong>Fig 2 </strong>displays an example log auto-generated by AccessData&#8217;s FTK Imager. The imaging log gives forensic experts some information about the physical capacity of the disk, serial number and some of the notes I have used. In this case, the image was a server that was running a virtual machine. FTK imager was run live in this instance in the emulated environment, and the image was outputted to the emulated physical disk. Another option is shutting down the virtual machine image and logically copying and verifying the file or indeed the whole of the servers physical disk. Shutting down a server may cause financial loss to a firm and disruption if the server is in use. If it is on image the machine while it is in that state while taking notes, that is my recommendation.</p>
<h3>Fig 2 &#8211; Example Forensic Imaging Log File Automatically Generated by FTK Imager Lite V3.1.1.8</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQEtNhRI4xwPrw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4Q5ZAnYNYo3t6CRvGL6HqvI2h0hIqO3-WNCMMf5xu24" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQEtNhRI4xwPrw" data-li-src="https://media.licdn.com/dms/image/C5612AQEtNhRI4xwPrw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4Q5ZAnYNYo3t6CRvGL6HqvI2h0hIqO3-WNCMMf5xu24" /></p>
<p><strong>Email E-Discovery Collection</strong></p>
<p>Anyone collecting emails should be sure that emails on the local computer mailbox match the server. If they don&#8217;t then it is good practice to receive from both anyway and let the software de-duplicate the items, so you obtain a complete picture of the emails in the forensic search. Computers were after all invented to take the labour out of tasks.</p>
<p>Emails can appear in many forms (Lotus Notes NSF archives, Microsoft PST/OST&#8217;s, or individual EMLX or MSG files) and may not even reside on the custodian&#8217;s hard disk or smartphone under investigation. Other places they could be discovered are on enterprise servers, as a fragment in the deleted areas of a hard disk or even on the cloud via services such as Gmail for business or Microsoft 365. The email archive may also carry encryption so you may get a Lotus Notes NSF email archive file; without the unlock ID and a tool to open you will run into trouble, which goes for password locked PST&#8217;s too.</p>
<p>A computer forensic collection of emails may be as simple as collecting a PST email archive file that resides locally on an individual&#8217;s laptop, server or user share.</p>
<p>A more complex instruction may need the collection of specific emails that contain only certain keywords on a Microsoft Exchange server while keeping the integrity of the email attachment/mailbox structure. In these more complex situations an <a href="http://www.linkedin.com/in/computerforensicsexpertwitness" rel="noopener">E-Discovery collection expert</a> and your client may need to cough up for <a href="http://sherpasoftware.com/" rel="nofollow noopener">Discovery Attender</a> by Sherpa Software, this excellent program plugs into your exchange server and can search, filter and extract onsite. You could also attach FTK with an enterprise agent or even image the whole disk and search from that image onsite.</p>
<p>I have created a summary guide below of the best tools in my experience in email E-Discovery collection:</p>
<h3>Summary of Email Formats and Best Tools for E-Discovery Email Collections</h3>
<ul>
<li><strong>Local PST/OST </strong>Just logically collect an image using FTK Imager or similar. Be sure to hash verify the collected items if copied and make notes!</li>
<li><strong>Webmail such as Gmail/Hotmail/Yahoo/365 Etc </strong>Use <a href="https://www.vound-software.com/individual-solutions#intella-pi" rel="nofollow noopener">Intella&#8217;s PI </a>or the chopped starting at $100 for a 10GB case limit. Using IMAP settings (and permission!) you can collect the whole remote email archive as the binary file and export as a PST file. All these actions carry a full audit log. Many webmail providers such as Gmail have a built-in option to backup and download the whole archive; you may also consider this.</li>
<li><strong>Microsoft Exchange Database </strong>It is possible to just download the whole EDB file and process in FTK 5.6 the full version or later. You could export different custodians as a PST, search, and filter if needed. If you need a few custodians, then something like <a href="http://www.messageops.com/software/" rel="nofollow noopener">MessageOps</a> is convenient. You can install the software on the server, and with admin, credentials run through and select the custodians you wish to export from. The results are outputted as nicely packaged PST&#8217;s along with a log file for verification. Dated indigenous X-merge can also export mailboxes as a PST, but it has a 2GB limit and can be a pain in more extensive collections.</li>
<li><strong>Lotus Notes </strong>The mailbox can be exported from the custodian machine in its entirety in the GUI options of the mail user interface. This approach is great if you have a few especially the admin ID file that contains the decryption keys. Then Proofinder or FTK 5.6 or later can be used to mount and read these archives. You may want to collect direct from the server. In the live environment, you may find the archives don&#8217;t copy. Use <a href="http://www.codesector.com/teracopy" rel="nofollow noopener">Teracopy</a> or Robocopy or something similar to copy stubbornly locked files in a live setting. It is quite likely Samsung, or similar doesn&#8217;t want its <a href="http://www-03.ibm.com/software/products/en/notesanddominofamily" rel="nofollow noopener">Lotus IBM Domino </a>database of 1000 users shut down for 20 hours while it is being imaged! If you have never encountered Lotus Notes before it is because it is antiquated and belongs in the dustbin of history; you needn&#8217;t a Delorian or the Doc to go back in time a few minutes in the dated GUI with fool anyone into thinking it is 1994!</li>
<li><strong>Loose or Deleted Emails </strong>These can be recovered from the server or local by using a <a href="http://compute-forensics.com/?portfolio=data-recovery" rel="nofollow noopener">data recovery</a> program such as the ugly but effective <a href="http://www.cgsecurity.org/wiki/PhotoRec" rel="nofollow noopener">photorec</a> as shown below <strong>Fig 3</strong>. Data Recovery should be made from a previously produced forensic image. If an image is not possible an experienced <a href="http://compute-forensics.com/?portfolio=email-discovery" rel="nofollow noopener">computer forensics collection</a> expert would run photorec live from an external disk and output the data to that same external disk. Emails may also be logically recovered from the email admin interface or reside on the server even though they have been deleted from the custodian&#8217;s machine.</li>
</ul>
<p><strong>Warning: Do not install data recovery software to the drive you wish to recover from or worse still output the retrieved data to the source drive.</strong></p>
<h3>Fig 3 &#8211; PhotoRec TestDisk&#8217;s Beautiful and Modern User Interface</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQG_NsBzFB2PPw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=9bBLPZlWS3j6UduFQoI2-PxPq_gGq6BigompMx-WE40" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQG_NsBzFB2PPw" data-li-src="https://media.licdn.com/dms/image/C5612AQG_NsBzFB2PPw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=9bBLPZlWS3j6UduFQoI2-PxPq_gGq6BigompMx-WE40" /></p>
<h3><strong>Physically Forensic Imaging Using a Hardware Writeblocker</strong></h3>
<p>Many Computer Forensic companies such as Compute Forensics choose to use a hardware write blockers in many instances. A writeblocker is just a device that halts any writes to the disk from the forensic examination system when copying or viewing. This is shown in <strong>Fig 4</strong>. A computer forensics examiner would then go on to attach this device to a USB 3.0 socket on the examination computer&#8217;s USB 3.0 port for optimum speed. Making sure the evidence disk is in &#8216;Locked Mode&#8217; it can be attached to the device. The disk should then show up in Windows Explorer and FTK Imagers &#8216;Add Evidence&#8217; GUI option. The device <em>should </em>now be safe as it is now attached to a hardware writeblocker.</p>
<p>Writeblocking devices used to cost £1000&#8217;s but recently Compute Forensics discovered a decent one built by CoolGear. The Coolgear forensic imaging device has USB 3.0 support and images 2.5&#8243; and 3.5&#8243; sizes of SATA drives. You can pick one of these up for £40.00. I, Alistair Ewing, have tested the CoolGear forensic writeblocker and am content with the performance. It is fast and reliable.</p>
<h3><strong>Imaging Bottlenecks</strong></h3>
<p>The device will only read/copy as fast as the slowest component. On average it takes 4-8 hours for one disk to complete despite companies boasting 500mbs second speeds the device will image anywhere from 1mbs to 80mbs-100mbs. A skilled examiner can copy up to 8 drives at once, much like spinning plates. Collection costs can start at around the £700 a day mark dependant. If you are a company instructing us, please don&#8217;t complain if your rickety 15-year-old IDE disk is taking too long to copy!</p>
<h3><strong>Fig 4 &#8211; CoolGear USB 3.0 Forensic Writeblocker Attached to a 3.5&#8243; SATA Hard Disk Drive</strong></h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQHiavegSls5XA/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=HW54MVmsnkVMT6r-yeCeVyDoR4Rlb-ANM1irRMN4jV0" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQHiavegSls5XA" data-li-src="https://media.licdn.com/dms/image/C5612AQHiavegSls5XA/article-inline_image-shrink_1500_2232/0?e=2129500800&amp;v=beta&amp;t=HW54MVmsnkVMT6r-yeCeVyDoR4Rlb-ANM1irRMN4jV0" /></p>
<h3><strong>Forensic Imaging Using any SATA/IDE to USB Adaptor and Software Blocking</strong></h3>
<p>Another unorthodox method I have used in the past when the drive attached to the write blocker won&#8217;t read, or you need a special adapter that isn&#8217;t IDE or SATA. This method uses a software blocker and a USB to SATA, IDE, memory card or whatever adaptor. Make sure the destination drive is a USB 3.0 external drive for speed. A software writeblocking program is used in this instance. Usage is simple but also easy to screw up.. Royally! The steps are:</p>
<p><strong>1)</strong> Plug in your destination drive.</p>
<p><strong>2)</strong> Start Ratool or Thumbscrew and select &#8216;Block USB Storage Devices&#8217; and then apply changes.</p>
<p><strong>3)</strong> Plug in a test USB disk and try and delete format it. Windows shouldn&#8217;t allow writing access to this disk.</p>
<p><strong>4)</strong> If it does repeat step <strong>2) </strong>&amp;<strong> 3) </strong>until the drive is blocked. When blocked it is safe to plug in the USB disk and adapter in the port that you plugged your test device into the system.</p>
<p><strong>5) </strong>Now you should have your destination writable (anything previously plugged in will be writeable too) and your evidence USB stick, Drive or Card plugged in but blocked.</p>
<p><strong>6)</strong> Use your favourite imaging software such as <a href="http://accessdata.com/product-download/digital-forensics/ftk-imager-lite-version-3.1.1" rel="nofollow noopener">FTK imager</a> or <a href="http://www.magnetforensics.com/magnet-acquire/" rel="nofollow noopener">Magnet Aquire</a>. Output the full physical disk to your destination disk. Be sure to make continuous notes of what you are doing, videos, pictures of the system and be sure to check the image has been MD5 verified by the hash sum, then you can be sure the copy is identical to the original.</p>
<h3><strong>Forensic Imaging Using a Forensic Bootdisk or USB</strong></h3>
<p>Using a bootdisk is the preferred method as you don&#8217;t need to waste time opening up a drive. The operating system uses the system as a terminal device, and the hard disks are by default blocked. This method works on most Macs, Windows and Linux systems.</p>
<h3><strong>Caine, Paladin &amp; Deft &#8211; 3 Free Computer Forensic Bootable Linux Distros</strong></h3>
<p>Firstly download a distro, my favourite is favourite is <a href="http://www.google.co.uk/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=web&amp;cd=1&amp;cad=rja&amp;uact=8&amp;ved=0ahUKEwiR8enrkKPPAhVjCcAKHeXcA_UQFggeMAA&amp;url=http%3A%2F%2Fwww.caine-live.net%2F&amp;usg=AFQjCNES4stuj9bYhjYNBZM6k7Ydz7Jjpg&amp;sig2=jKaTTxJVWfQuCrQ0pfR7MQ" rel="nofollow noopener">Caine</a>. Famous actor Michael Caine assembles it (Only kidding it is made by Italian consultant <a href="http://www.nannibassetti.com/" rel="nofollow noopener">Nanni Bassetti</a>!). Another great free distro that you have to register to obtain is <a href="http://sumuri.com/" rel="nofollow noopener">Suri&#8217;s Paladin</a>, see <strong>Fig 4</strong>. Download the ISO from the <a href="http://www.caine-live.net/" rel="nofollow noopener">website</a> then burn the ISO to a DVD or use <a href="http://rufus.akeo.ie/" rel="nofollow noopener">Rufus</a> with default settings to make a bootable USB disk. To produce a bootable USB in Rufus merely select the USB stick, click the disk logo and locate the ISO you just downloaded then hit the start button and wait for your bootable USB to be prepared. Always have a copy of <a href="http://www.deftlinux.net/" rel="nofollow noopener">DEFT</a> or <a href="http://e-fenseinc.sharefile.com/share?#/getinfo/sda4309a624d48b88" rel="nofollow noopener">Helix</a>handy on a compact disk rather than DVD in case you are working on a device that won&#8217;t boot from DVD or USB. from a device that won&#8217;t boot from DVD or USB.</p>
<h3>Fig 4 Paladin&#8217;s ToolBox Imaging Graphical User Interface in Linux Running in Live Mode on a Host Machine</h3>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C4E12AQEYega-cd7JKQ/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4oBywWAL1yiAPQzAKEiA3snMu77Bt9H-vsN_GIcs0pk" width="744" data-media-urn="urn:li:digitalmediaAsset:C4E12AQEYega-cd7JKQ" data-li-src="https://media.licdn.com/dms/image/C4E12AQEYega-cd7JKQ/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=4oBywWAL1yiAPQzAKEiA3snMu77Bt9H-vsN_GIcs0pk" /></p>
<p><strong>Booting Your Computer Forensics Distribution in the Bios</strong></p>
<p>Before any booting of the system from a switched off state do some research into what key combinations trigger the boot disk. It varies, on a Mac hold the &#8216;Option Key&#8217; or &#8216;C&#8217;, on a Windows system it could be anything from &#8216;F1&#8217; or &#8216;Del&#8217;. Take time to look through <a href="http://craftedflash.com/info/how-boot-computer-from-usb-flash-drive" rel="nofollow noopener">this </a>list before switching to the system in preparation for booting into a Forensic OS. If you get it wrong, you may boot into the operating system if this event occurs switch the computer off by the button (if safe) or pull out the power cord.</p>
<p>Then the general idea is to use a GUI program such a Guymager as shown in <strong>Fig 5 </strong>to acquire the media to the destination drive without removing the disk while preserving the integrity of the drive. You need to remember to unlock your destination drive.</p>
<p><strong>Fig 5 Guymager Forensically Imaging 2 Attached Disks USB Disk</strong></p>
<p><img decoding="async" src="https://media.licdn.com/dms/image/C5612AQEtca7bnr82rw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=BbjwN4lWg0i155NrJos2y3jQbkTCX3EhoEL3yl_nSPw" width="744" data-media-urn="urn:li:digitalmediaAsset:C5612AQEtca7bnr82rw" data-li-src="https://media.licdn.com/dms/image/C5612AQEtca7bnr82rw/article-inline_image-shrink_1000_1488/0?e=2129500800&amp;v=beta&amp;t=BbjwN4lWg0i155NrJos2y3jQbkTCX3EhoEL3yl_nSPw" /></p>
<h3><strong>Remote Forensic Imaging over a Network</strong></h3>
<p>A computer forensic examiner would place a clean virus free computer on the network and attach to the companies domain. Using Encase Enterprise or FTK v5.6+ a computer forensic examiner, with root access, could push an agent to gain access to a remote system. The RAM could be examined for malware and Physical Disk in Read-Only mode. The examiner could then review the computer in real time to produce a logical forensic skeleton image of only the files that are of interest. Alternatively, the examiner could copy the disk remotely and have it outputted to a secure location on the server or locally.</p>
<p>If the user profile exists on the server, it might be sufficient to mount the remote disk or user share in logically in Windows by selecting &#8216;Map Network Drive&#8217; and using FTK Imager to image the contents locally logically. The local machine should be physically copied where possible in addition to the remote user directory for completeness.</p>
<h3><strong>Forensic Imaging Mobile Phones &#8211; iOS, Blackberry, Windows and Android</strong></h3>
<p>If you come across a phone place it in aeroplane mode or switch it off immediately as it is easy to wipe a device remotely using iCloud&#8217;s &#8216;Find My Phone&#8217; or Similar apps of that ilk.</p>
<p>For a mobile phone forensics expert Magnet&#8217;s free software Aquire, CellBrite, UFED and XRY can be used to grab an image logically and physically of a mobile device. A logical grab will obtain the filesystem and no deleted data (except items in the SQL databases that can be logically recovered and scraped from these databases).</p>
<p>A physical &#8216;Hex Dump&#8217; of a mobile device is the holy grail of mobile acquisition. Hex dumping entails the device to be rooted or jailbroken as so a 3rd party app can exploit the phone allowing the device to be imaged much like a computer hard drive. From this image, deleted data can is gathered.</p>
<h3>Mobile Phone Backups</h3>
<p>It is also worth a mention that Mobilebackups in the form of BBB/IPD Blackberry backups and Mobilesync backups for Apple may exist on the computer system seized that can be read much like actual mobile device if for some reason the device is no longer available. These backups may contain messages, photos and chat conversations.</p>
<p>Thank you for reading my overview of forensic imaging. I hope it was informative.</p>
<p>By Alistair Ewing Director of Compute Forensics</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
