O'Reilly logo

Computer Forensics: Incident Response Essentials by Warren G. Kruse, Jay G. Heiser

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Chapter 3. The Basics of Hard Drives and Storage Media

We hear a lot of questions about hard drives and what to do with them. The answer is simple: Make an image copy and then restore the image to a freshly wiped hard drive for analysis (as we describe in Chapter 7). After you’ve restored the image, you have to mount it so that it can be recognized during your analysis—this step is different depending upon the filesystem used on the original drive. At this point, you have two different forms of evidence—the original drive and one or more exact copies of it. Remember, we are talking about evidence that may eventually wind up in either criminal or civil court, so you have to take proper precautions to ensure that the evidence is not damaged or ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required