Data Acquisition
Why do we Acquire?
What is important to remember about the first image taken?
- The original image needs to be saved, and copies are made to do the actual work on
Order of Volatility?
What are the two types of data acquisition?
- dynamic/live
Static Acquisition
Dynamic Acquisition
Which type of acquisition is typically done first?
Raw Format
What are the benefits of Raw Format?
- popular on most forensic tools; gives flexibility to move between different frameworks
What are some things to be aware of with Raw Format?
What tool allows a disk to be imaged and split into multiple smaller files?
Proprietary Format
- compress the data for space efficiency, but makes the imaging and analysis process slower
What are the advantages of using proprietary formats?
What are the disadvantages of using proprietary formats?
What are the most notable proprietary formats?
Open Source Format
Data Acquisition vs. Copying
What needs to be considered when copying an image?
What are the two acquisition methods?
- from disk drive to disk drive (cloning)
Imaging
Cloning
Live Acquisition
Why is volatile data so fragile?