People asked for this stuff so here are a few that I have found..Both are very interesting.

David Westerfield case; Computer forensic examination
http://members.cox.net/jeneal/Prelim...pts/PVW312.txt


US V. Zacarias Moussaoui; CART analysis of Laptop
http://notablecases.vaed.uscourts.go...cs/68089/0.pdf

From the Moussaoui case...looky here...dd!
The FBI uses three different methods to duplicate or image a hard drive:
(1) GNU/Linux routine dd command via Red Hat Linux 7.1 (hereafter Linux dd );