File Formats and Common Forensic Software Programs Flashcards

1
Q

The Advanced Forensic Format AFF

A

was invented by Basis Technology. It is an open file standard with three variations: AFF, AFM, and AFD. AFF stores all data and metadata in a single file. AFM stores the data and metadata in separate files, AFD stores the data and metadata in multiple small files. Sleuth Kit and Autopsy both support AFF.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

EnCase

A

Is a proprietary format that is defined by Guidance Software for use in its EnCase tool to store hard drive images and individual files. It includes a hash of the file to ensure nothing was changed when it was copied from the source.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

EnCase Software

A

very widely used forensic toolkit. This allows the examiner to connect an Ethernet cable or null modem cable to a suspect machine and to view the data on that machine.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Forensic Toolkit FTK

A

Forensic analysis tool that is very popular with law enforcement. Can select which hash to use to verify the drive when you copy it, which features you want to use on the suspect drive, and how to search.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Sleuth Kit

A

A collection of command-line tools that are available as a free download.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Autopsy

A

A free download, cost effect option for a forensics toolkit.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Disk Investigator

A

Free utility that comes as GUI for use with Windows operating systems. Not as full featured as EnCase, but remarkably easy to use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly