People asked for this stuff so here are a few that I have found..Both are very interesting.

David Westerfield case; Computer forensic examination

US V. Zacarias Moussaoui; CART analysis of Laptop

From the Moussaoui case...looky here...dd!
The FBI uses three different methods to duplicate or image a hard drive:
(1) GNU/Linux routine dd command via Red Hat Linux 7.1 (hereafter Linux dd );