Disk Imaging Flashcards
In imaging vs copying, imaging captures…
slack space
unallocated space
deleted files
file metadata
In imaging vs cloning, imaging is…
not bootable
compressed
checksummed
examinable with forensic tools
Types of volumes that can be imaged
Physical volumes
Logical volumes
Why image physically?
To get the full drive.
Why image logically?
Usually faster
How do you image if the disk is encrypted?
Logically
Forensic Triage
Collects the most useful files from a disk
Live imaging
Imaging while a machine is on.
Boot imaging
Booting into a different machine to take the image.
Dead box imaging
Pulling a hard drive and imaging it.
What tool lets you check for encryption?
EDD
When would you boot image?
Whenever you cannot remove the hard drive from the machine and the drive is not encrypted.