People asked for this stuff so here are a few that I have found..Both are very interesting.
David Westerfield case; Computer forensic examination
US V. Zacarias Moussaoui; CART analysis of Laptop
From the Moussaoui case...looky here...dd!
The FBI uses three different methods to duplicate or image a hard drive:
(1) GNU/Linux routine dd command via Red Hat Linux 7.1 (hereafter Linux dd );