Disk cloning for evidence
Hello all,
I need to take a copy or better yet a "cloning" of a HDD to search for evidence and other things.
Offcourse this needs to be done without touching the timestamps on the original HDD, I'll put the clone back in the machine and take the original along.
Afterwards I'll put it in another machine and copy it again to work of that copy and leave the original alone...
Then I'll hang that copy as a slave and investigate it.
The Computer has Win98 as OS.
Now ...my questions:
1- Does anyone know any good Disk cloning tools or would Symantec Ghost be ok ?
2- What tools do I use for searching the disk for evidence ...It's not hacked ...it's just to see the surfing and chatting habbits of someone. (it's not illegal the pc is not this persons property but from the person that gave me this "job" and is owner of this PC) and confront him/her with it.
3- Does the way I plan to do this look ok to you forensic experts or would you choose another path/way to do things.
Many thanks for any help,
If I need to give more info let me know.
Acquiring evidence files using disk cloning techniqiues
HI
i was reading your post on disk cloning... I would just like to point a few things out as this is what i have to do day in day out..
1 where possible removed the suspect disk and use such a device as a write blocker (fastbloc, or tableau device) this blocks the writes to the hard disk when it is fired up.. then use some software such as encase of FTK to create image files this will allow you to demonstrate that you have indeed maintained data continuity . when these image files are created they create and md5 hash which can be used to verify that the data has not been altered.