Like everything we start at acquisitions the how we obtain electronic evidence and how to preserve the integrity thereof. We have a few option in those categories:
- FTK Imager : Yes, this is a commercial product however for the imager you do not need licensing and I personally like using this programme has the abillities to capture volatile data along with giving you the option in which format you would like to save your image. This programme also hashes the original media and calculates the MD5 checksum along with the SHA-1 and recalculates it afterwards, when the hashes matches you know the integrity of your evidence is proven.
- Raptor : The most important factor which makes it a worhtwhile product for the rookie examiner is that is is incredibly easy to use as the GUI interface eliminates the pesky use of command line. The product is widely supported by all computers and hardware that can support linux Ubuntu. One of the most contributing factors is that you do not need to disassemble to hardware and allows you to preview the internal hard drives with never having to open the machine. It also allows for you to acquire without the use of hardware writeblockers as it has been modified to write-block all media upon boot thus preventing accidental writes. (Lets face it hardware writeblocker are expensive no matter where you live).
- Paladin is a modified Live Linux distribution based on Ubuntu that
simplifies the process creating forensic images in a forensically
sound manner. PALADIN was designed with the understanding that many of
those tasked with creating forensic images are not comfortable with
using the command-line but still want to utilize the power of Linux.
PALADIN was also designed with the understanding that many agencies or
companies have limited budgets PALADIN CD version is always free!It is incredibly easy to use and eliminates the need to remember confusing commands and switches,it will work on any computer or hardware that is supported by Ubuntu Linux,allows a user to safely image and preview internal hard drives without having to disassemble the computer or laptopand it has been modified to write-protect all attached media upon
boot thereby preventing accidental writes or having to use expensive
physical write-blockers.
You can download both these products at:
www.accessdata.com
http://forwarddiscovery.com/Raptor
http://www.sumuri.com/index.php/joomla/weblinks