A disk image is a full disk copy of the data making up the partition table, file allocation tables and data partitions without regard for operating system. A disk image should be made prior to performing any forensic analysis of the disk. Creating a disk image is important in forensics for several reasons:
1. Ensures that disk information is not inadvertently changed during analysis.
2. By performing an original disk image and storing the original disk, it is possible to reproduce forensic test results with an exact reproduction of analysis methods on the original evidence.
3. Disk imaging will capture information invisible to the operating system in use (e.g. hidden partitions, ext3 partitions on a Windows machine, etc.)
2.Forensic Write Blockers :
Write blockers
are devices that allow acquisition of information on adrivewithout creating the possibility of accidentally damaging the drive contents. They do this by allowing read commands to pass but by blocking write commands, hence their name. There are two ways to build a write-blocker: the blocker can allow all commands to pass from the computer to the drive except for those that are on a particular list. Alternatively, the blocker can specifically block the write commands and let everything else through** USB write blockers are also available.
3.Data
Recovery, Carving and Forensic Analysis :
Data recovery is the process of salvaging data from damaged, failed, corrupted, or inaccessiblesecondary storagemedia when it cannot be accessed normally. Often the data are being salvaged from storage media such as internal or externalhard disk drives, solid state drives (SSD), USB flash, storage tapes, CDs, DVDs,RAID, and other electronics. Recovery may be required due to physical damage to the storage device or logical damage to thefile system that prevents it from being mounted by the hostoperating system
Analysis: The art of analyzing data recovered or data present on the disk to be able draw a conclusion on a specific point, or to find evidence/ proof of a activity done previously and presently in question and vice versa. There are several softwares to do this, we can provide the best as to suit the need of the client.
4.Forensic Workstation :
A workstation is a
high-end microcomputer designed for technical or scientific
applications. Intended primarily to be used by one person at a time,
they are commonly connected to a local area network and
run multi-user operating systems. The term workstation has also been
used to refer to a mainframe computer terminal or a PC connected to
a network
The Multi tasking capability of a workstation attracts Cyber Investigators and Experts to work on it, so that more work could be done in less span of time, as imaging and analysis both consume most of the time.
There are many customizable products in this range are available to suit
the needs of a specific client.