Skip to Content
Digital Forensics Basics: A Practical Guide Using Windows OS
book

Digital Forensics Basics: A Practical Guide Using Windows OS

by Nihad A. Hassan
February 2019
Beginner
347 pages
7h 31m
English
Apress
Content preview from Digital Forensics Basics: A Practical Guide Using Windows OS
© Nihad A. Hassan 2019
Nihad A. HassanDigital Forensics Basicshttps://doi.org/10.1007/978-1-4842-3838-7_5

5. Acquiring Digital Evidence

Nihad A. Hassan1 
(1)
New York, New York, USA
 

How to acquire volatile and nonvolatile memory

The main task of a computer forensics investigator is to acquire and analyze computing devices’ memory images. In a nutshell, a memory image—widely known as a forensic image—is a static snapshot of all or part of the data on a computing devices’ secondary storage (e.g., HDD, SSD), attached storage device (e.g., USB thumb drive, external hard drive, magnetic tape), or RAM memory (when performing live acquisition on running systems). We can think of this image as a container of data, where you can store individual files or ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Learn Computer Forensics - Second Edition

Learn Computer Forensics - Second Edition

William Oettinger
Security in Computing, 6th Edition

Security in Computing, 6th Edition

Charles Pfleeger, Shari Lawrence Pfleeger, Lizzie Coles-Kemp

Publisher Resources

ISBN: 9781484238387Purchase LinkPublisher Website