
More about the book
Forensic image acquisition is crucial for postmortem incident response and evidence collection. Digital forensic investigators gather, preserve, and manage digital evidence for civil and criminal cases, policy violations, disputes, and cyber attack analyses. This guide offers an in-depth examination of securing and managing digital evidence using Linux-based command line tools. It covers the entire forensic acquisition process and addresses various practical scenarios related to imaging storage media. Key learning points include performing forensic imaging on magnetic hard disks, SSDs, flash drives, optical discs, magnetic tapes, and legacy technologies; protecting evidence media from accidental modification; and managing large forensic image files, including storage capacity, image format conversion, compression, splitting, duplication, secure transfer and disposal. The guide also emphasizes preserving and verifying evidence integrity with cryptographic methods, public key signatures, and timestamping. It explores newer drive technologies like NVME and SATA Express, as well as managing drive security through ATA passwords, encrypted drives, and OS-encrypted systems. Additionally, it addresses acquiring usable images from complex situations such as RAID systems and damaged media. With its focus on digital forensic acquisition and evidence preservation, this resource is invaluable for digital forensic investigators lookin
Book purchase
Practical Forensic Imaging, Bruce Nikkel
- Language
- Released
- 2016
- product-detail.submit-box.info.binding
- (Paperback)
Payment methods
No one has rated yet.
- Title
- Practical Forensic Imaging
- Subtitle
- Securing Digital Evidence with Linux Tools
- Language
- English
- Authors
- Bruce Nikkel
- Publisher
- No Starch Press
- Released
- 2016
- Format
- Paperback
- Pages
- 324
- ISBN10
- 1593277938
- ISBN13
- 9781593277932
- Series
- Description
- Forensic image acquisition is crucial for postmortem incident response and evidence collection. Digital forensic investigators gather, preserve, and manage digital evidence for civil and criminal cases, policy violations, disputes, and cyber attack analyses. This guide offers an in-depth examination of securing and managing digital evidence using Linux-based command line tools. It covers the entire forensic acquisition process and addresses various practical scenarios related to imaging storage media. Key learning points include performing forensic imaging on magnetic hard disks, SSDs, flash drives, optical discs, magnetic tapes, and legacy technologies; protecting evidence media from accidental modification; and managing large forensic image files, including storage capacity, image format conversion, compression, splitting, duplication, secure transfer and disposal. The guide also emphasizes preserving and verifying evidence integrity with cryptographic methods, public key signatures, and timestamping. It explores newer drive technologies like NVME and SATA Express, as well as managing drive security through ATA passwords, encrypted drives, and OS-encrypted systems. Additionally, it addresses acquiring usable images from complex situations such as RAID systems and damaged media. With its focus on digital forensic acquisition and evidence preservation, this resource is invaluable for digital forensic investigators lookin