Forensics Flashcards
1
Q
dd
A
- A command line utility used to copy disk images using a bit by bit copying process
2
Q
FTK Imager
A
- a data preview and imaging tool that lets you quickly assess electronic evidence to determine if further analysis with a forensic tool is needed
- Tool for creating forensic images of computer data
3
Q
Memdump
A
- A command line utility used to dump system memory to the standard output stream by skipping over holes in memory maps
4
Q
WinHex
A
- A commercial disk editor and universal hexadecimal editor used for data recovery and digital forensics
- Multi-function disk and binary data editor used for low-level data processing, data recovery and digital forensics
5
Q
Autopsy
A
- A digital forensics platform and graphical interface to the Sleuth Kit and other digital forensics tools