Dead imaging
Dead imaging is conducted on media that is not powered on and, in the case of hard drives, removed from the potentially compromised system. In terms of evidence preparation, this method is most comprehensive as it allows for the complete preservation and analysis of a physical volume. There are several methods and tools available, both commercial and freeware, that allow for proper imaging. In addition to software, often incident response analysts will make use of a hardware write blocker. These devices ensure that no changes are made to the suspect media. As we discussed in Chapter 1, Understanding Incident Response, it is critical to be able to demonstrate to a court of law that no changes were made to the original evidence. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access