![]() ![]() FTK Imager allows you to create an image in the following formats: 1) Raw (dd.001), 2) SMART (S01), 3) E01 (EnCase), and 4) AFF. The image file itself can be created in a variety of formats. We have two main tools that allow us to do this: ProDiscover and FTK Imager. For this course, we will be using mostly the disk-to-image acquisition method. There are different data acquisition tools and techniques. In forensic procedures, these are two steps: 1) data acquisition, and 2) image verification. The evidence image must be a true copy of the original for it to be courtaccepted. As forensic investigators, sometimes we must create an image from the original evidence. It is important that you explain this information before you start the activity. You will use Imager to explore and verify images You will create forensic images from physical evidence The information about imaging and hashing is a core component of the course and part of the CLOs. Transcribed image text: Task 1: Basic Imaging -FTK Imager Task Objectives. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |