hard drive

If you are new to the world of digital forensics, you may come across the term “forensic image.” What exactly is a forensic image? A forensic image is a bit for bit copy of the source device and is stored in a forensic image format. A forensic image allows you to conduct your investigation on an exact copy of the source device. Now your source device may be a thumb drive, hard drive, or SSD drive.

You do not want to do your exam on the original evidence due to its fragility. It is very easy to change digital evidence inadvertently. Using a forensic image protects the data during the examination, so we cannot accidentally change the data. Some standard formats of the forensic image are DD, E01, and AFF.

DD is one of the oldest imaging tool available for forensic investigators. It originally was a UNIX command but has now been migrated to all the major operating systems. There are now unique versions of DD that you can use, one of the more common versions is dc3dd, has been developed by Jesse Kornblum.

E01 is the expert witness format used by the EnCase forensic software suite. E01 differs from DD and that it creates a “header” that contains the evidence name/number, acquisition dates and times, notes from the investigator, and information about the forensic tool that created the forensic image. This format also creates a CRC value every 64 sectors to help verify the data in the forensic image has not changed. AFF is the advanced forensics format. This is an open-source forensic image format that was developed by Simson Garfinkel and Basis Technology. In my experience, DD images and E01 images are considered to be the “standard” for forensic images. I do not remember the last time I did not receive a forensic image that was not in either format. If you want to learn more about the forensic images in the process used to create them, please check out my book “Learn Digital Forensics” https://www.amazon.com/dp/B086WBP289 on Amazon.com.
Share on facebook
Facebook
Share on twitter
Twitter
Share on linkedin
LinkedIn
Share on email
Email
Blog

Is Court-martialing Military Retirees Unconstitutional? Two Cases May Change UCMJ Jurisdiction.

It is a little known fact: only some military retirees remain subject to the UCMJ after leaving service. Enlisted Sailors and Marines who complete 20-29 …

Read More →
Blog

Army Holds Fort Hood Leadership Accountable After an Investigation Report Finds “toxic” Culture That “fueled” Sexual Harassment

In the months since the discovery of the dismembered and burned remains of U.S. Army Specialist Vanessa Guillen, a Fort Hood soldier who disappeared on …

Read More →
Blog

New Year Could Bring First Ever Court-Martial For an Air Force General Officer

On January 27, 2021, the Air Force will hold a preliminary hearing to determine if there is enough evidence to send the case of Air …

Read More →

Deprecated: jquery-slick is deprecated since version 2.7.0! Use Swiper instead. in /www/bileckitiponlllc_685/public/wp-includes/functions.php on line 5049
Scroll to Top

Request A FREE Case Evaluation

You deserve a fighting chance on your day in court. When it comes time to decide who your attorney will be to defend your UCMJ charges, make that decision count.***

*** All information submitted will be kept confidential and private. An attorney client relationship is not established by submitting this initial contact information to our office.