September 2016
Intermediate to advanced
320 pages
8h 32m
English

This chapter discusses the physical attachment of subject storage media to an examination host, identification of the subject device on the system, and querying the device firmware for information. You’ll also learn about methods for removing HPA and DCO, unlocking ATA passwords, and decrypting self-encrypting drives. The chapter ends with several special storage topics. Let’s start by examining the subject PC hardware.
When a PC or notebook is seized in the field or delivered to a forensic lab for examination, more than just the internal disks can be examined. Included ...
Read now
Unlock full access