Professional Documents
Culture Documents
CHFI v3 Module 12 Data Acquisition and Duplication
CHFI v3 Module 12 Data Acquisition and Duplication
Forensic Investigator
Module XII
Data Acquisition and
Duplication
Scenario
Adams Central Band Director Jeremy Johnson, 26, of 227 West South St., was
formally charged on September 21,
21 2006 with seven counts of child seduction and 41
counts of possession of child pornography. Investigators found hundreds of images of
child pornography on Johnson’s home computer.
Johnson
h was accused
d off seducing
d i a senior
i ffemale
l student
d at Adams
d Centrall d
during
i the
h
previous school year. The girl was then 18. Johnson had been taking part in a special
sharing service over the Internet and appeared to have been trading child porn back
and
d forth
f th with
ith other
th collectors.
ll t
Det. Sgt. Steve Cale and Det. Gary Burkhart initiated the investigation and collected
Johnson’s desktop computer and laptop. During the investigation, they found that
there were over 500 images that appeared to be of children less than age 18 in a state
of nudity, engaged in various stages of sexual activity. They also found some emails
that consisted of pornographic messages.
Source: http://www.news-banner.com/index/news-app/story.4999
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Module Objective
~ D t A
Data Acquisition
i iti T Tools.
l
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Module Flow
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Determining the Best Acquisition
Methods
~ Forensic investigators acquire digital evidence using the
following methods:
• Creating a bit-stream disk-to-image file.
• Making a bit-stream disk-to-disk copy.
• Creating a sparse data copy of a folder or file.
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Data Recovery Contingencies
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Need for Data Duplication
~ Data duplication
p is essential for the p
proper
p
~ D
Destructive
i devices
d i can b
be planted
l d iin the
h
~ Data fragments
g can be overwritten,, and data
or destroyed.
destroyed
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
MS-DOS Data Acquisition Tool: DriveSpy
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Using Windows Data Acquisition Tools
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
FTK Imager
~ FTK Imager allows you to acquire physical device images and logically
view data from FAT, NTFS, EXT 2 and 3 as well as HFS and HFS+ file
systems.
~ http://www.accessdata.com
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Acquiring Data on Linux
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
dd command
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Extracting the MBR
~ Source Machine
~ Target
g Machine
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
dd Command (Windows XP Version)
~ Linux dd utility ported to Windows.
dd.exe if=\\.\PhysicalDrive0
of=d:\images\PhysicalDrive0.img
f d \i \ h i l i 0 i --md5sum
d5 --verifymd5
if d5 --
md5out=d:\images\PhysicalDrive0.img.md5
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Mount Image Pro
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Snapshot Tool
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Snapback DatArrest
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Data Acquisition Tool: SafeBack
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Hardware Tool: Image MASSter Solo-3
Forensic
~ Designed
g exclusivelyy for forensic
data acquisition.
~ Th ImageMASSter
The I MASS Solo-3
S l F
Forensic
i
data imaging tool is a light weight,
portable hand-held device that can
acquire data to one or two evidence
drives at speeds exceeding 3GB/min.
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Hardware Tool: LinkMASSter-2
Forensic
~ The LinkMASSter II is a high-speed forensic
data acquisition device that provides the tools
necessary to seize data from a Suspect’s
unopened
p Notebook
b or PC using
g the FireWire
1394A/B or USB 1.0/2.0 interface.
• High-speed Operation
• Multiple Capture Methods
• Write Protection
• Multiple Media Support
• WipeOut
• Audit Trail and Logs
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Hardware Tool: RoadMASSter-2
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Data Duplication Tool: R-drive Image
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
R-drive Image
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Data Duplication Tool: DriveLook
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Drivelook
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Data Duplication Tool: DiskExplorer
~ DiskExplorer aides examiners to investigate any drive and recover
data.
~ Two versions of DiskExplorer exist:
• DiskExplorer for FAT
• Disk Explorer for NTFS
~ The tool also has provisions to navigate through the drive by jumping
to the:
• Partition table.
• B
Boot record.
d
• Master file table.
• Root directory.
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
DiskExplorer
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Save-N-Sync
~ The quickest, easiest, and most
economical way to synchronize
a small number of folders.
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Save-N-Sync
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Hardware Tool: ImageMASSter
6007SAS
~ The ImageMASSter 6007SAS is the only
h dd
hard drive
i d duplication
li i unit i iin the
h
market that supports SAS (Serial Attach
SCSI) hard drives.
~ It copies simultaneously at very high
speed from SATA/SAS/SCSI/IDE hard
d i
drives, tto any 7 SAS/SATA/IDE target
t t
hard drives.
~ The ImageMASSter 6007SAS is a
Windows based machine with one giga-
bit network connection, which allows
d
downloading
l di or uploading
l di fil
files tto or
from drives, using network drives.
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
ImageMASSter 6007SAS (cont’d)
~ Features:
• Standalone HD mode
• Mirroring
• Spanning
• Fast
F di
disk-to-disk
k di k copies
i
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Tape Duplication System: QuickCopy
Copyright © by EC-Council
EC-Council All rights reserved. Reproduction is strictly prohibited
Summary