IS & F Lecture #29 30 - Computer Forensics-Data Acquisition
IS & F Lecture #29 30 - Computer Forensics-Data Acquisition
Lecture # 30
Data Acquisition
Understanding Storage Formats for
Digital Evidence
• Three formats
– Raw format
– Proprietary formats
– Advanced Forensics Format (AFF)
• Features offered
– Option to compress or not compress image files
– Can split an image into smaller segmented files
– Can integrate metadata into the image file
• Disadvantages
– Inability to share an image between different tools
– File size limitation for each segmented volume
• Types of acquisitions
– Static acquisitions and live acquisitions
• Four methods
– Bit-stream disk-to-image file
– Bit-stream disk-to-disk
– Logical disk-to-disk or disk-to-disk data
– Sparse data copy of a file or folder