Live imaging
A live image can be captured from a running system utilizing FTK Imager in much the same way as you would for dead imaging. In this case, the one major difference is that FTK Imager will be run from a USB device connected to the system. This allows the incident response analyst to image the drive without changing the system. While certain files and registry settings will be updated, imaging in this fashion will not change system files in the same way that installing FTK Imager would on a potentially compromised system.
In terms of preparation, the analyst should have a preconfigured USB drive with separate tools and evidence partitions. As we discussed previously, the evidence partition should be wiped prior to any use. Also, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access