Non-Volatile Forensic Data Acquisition using dcfldd
Автор: Security Dude
Загружено: 2026-02-12
Просмотров: 34
Описание:
In this video, I demonstrate the complete workflow for performing a non-volatile forensic acquisition within a Docker-isolated lab environment. Using a simulated suspect system and a forensic workstation, we walk through the critical phases of the acquisition process to ensure bit-for-bit integrity.
Key Topics Covered:
Environment Preparation: Confirming suspect containers and shared evidence volumes.
Storage Identification: Identifying target storage media and file system formats (ext4).
The Collection Phase: Using the dcfldd tool for imaging, including simultaneous hashing and logging.
Integrity Verification: Comparing SHA-256 hash values of the original suspect image against the forensic copy to mathematically prove integrity.
Best Practices: Discussion on legal authority, hardware write blockers, and managing environmental factors like heat and power stability.
Command used in this video:
dcfldd if=/evidence/suspect.img \
of=/evidence/forensic_image.dd \
hash=sha256 \
hashlog=/evidence/hash.txt \
conv=noerror,sync
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: