Forensics Forensic Acquisition.

Slides:



Advertisements
Similar presentations
Ali Baydoun1 Controllers (hard drive controllers).
Advertisements

COEN 252 Computer Forensics Hard Drive Geometry. Drive Geometry Basic Definitions: Track Sector Floppy.
CSN08101 Digital Forensics Lecture 6: Acquisition
IT Essentials PC Hardware & Software v5.0
This courseware is copyrighted © 2011 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
PC Support & Repair Chapter 3 Computer Assembly- Step by Step.
Improving Networks Worldwide. UNH InterOperability Lab Serial Advanced Technology Attachment (SATA) Use Cases.
Electronics Confidential Information © 3M 2005, All Rights Reserved Enterprise Computing Applications Charlie Staley January 2007.
Hard Disk Drives. ATA is the current standard, it uses regular molex power connectors and IDE cables. SATA is a newer product (also SATA2 is already in.
Universal Serial Bus USB Instant connection of external devices No adapter cards needed Mouse, joysticks, thumbnail drives PC standard Megabits.
Computer Hardware Components for Desktop
G043 – Lecture 02 Inside A Desktop PC Mr C Johnston ICT Teacher
IT Essentials PC Hardware & Software v4.1 Chapter 1 – Introduction to the PC Jeopardy Review Darren Shaver (Some questions originally from Stacie Bender)
UNH InterOperability Lab Serial Advanced Technology Attachment (SATA) Use Cases.
Improving Networks Worldwide. UNH InterOperability Lab Serial Attached SCSI (SAS) Use Cases.
Secondary Storage Unit 013: Systems Architecture Workbook: Secondary Storage 1G.
A+ Guide to Managing and Maintaining Your PC, 7e
COEN 252 Computer Forensics
CONNECTORS AND POINTS Elizabeth Viverette. 20-PIN P1  Main power connector for early ATX motherboards.
Copyright © 2007 Heathkit Company, Inc. All Rights Reserved PC Fundamentals Presentation 20 – The Hard Drive Interface.
PC Maintenance: Preparing for A+ Certification
A+ Guide to Managing and Maintaining Your PC, 7e Chapter 1 Introducing Hardware.
Mr C Johnston ICT Teacher BTEC IT Unit 02 - Lesson 01 Back to Basics.
I T Essentials I Chapter 3 JEOPARDY.
Computer Insides and Out Computer Basics 1.1. Basic Personal Computer System  A computer system consists of hardware and software components.  Hardware.
Internal components, Backing Storage, Operating Systems Software
… when you will open a computer We hope you will not look like …
Figure 1-2 Inside the computer case
Storage Devices Chapter 7. Floppy Drive Overview The floppy drive subsystem consists of three main parts: ▫the electronic circuits or the controller,
Strata IT Training Chapter 10 Advanced Storage Topics.
Computer Forensics Infosec Pro Guide Ch 6 Testing Your Tools.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco PublicNew CCNA Jianxin Tang IT 1 V4.0 Ch3. Computer Assembly—Step by Step.
IT Essentials v4.1 PC Hardware & Software Chapter 3 – Computer Installation Jeopardy Review v1 Darren Shaver Kubasaki High School Okinawa, Japan Chapter.
D ISCOVERING IDE D EVICES. IDE OVERVIEW The hard drive controller is responsible for converting signals made by the system CPU to signals that the hard.
PARTS OF THE COMPUTER BY JENNY DENG. CASE The case is like a skeleton. Everything is attached to it. It holds and protects the components. It is the surroundings.
Hard Drives aka Hard Disk Drives Internal, External, and New Solid State Drives.
1 COMPUTER ARCHITECTURE (for Erasmus students) Assoc.Prof. Stasys Maciulevičius Computer Dept.
HARD DISKS. INTRODUCTION TO HARD DISKS  Hard disk is the core fundamental component of the Computer system.  A mass storage device that stores the permanent.
Made By : Gagandeep Singh CompTIA A+ Certified. PORTS ON MOTHERBOARD  PS/2 PORT  SERIAL PORT  PARALLEL PORT  VGA PORT  DVI PORT  USB PORT  MINI.
This courseware is copyrighted © 2016 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
PC COMPONENTS. System Unit Cases This is the cabinet that holds the main components of a computer. It includes a plastic front panel for aesthetic purpose.
IDE and SATA standards Group: Hoàng Thị Thanh Nhàn Hoàng Thị Lan Chung Đinh Thị Bình.
Copyright © 2016 by McGraw-Hill Education. All rights reserved. Mike Meyers’ CompTIA A+ ® Guide to Managing and Troubleshooting PCs Fifth Edition Copyright.
A+ Guide to Managing and Maintaining your PC, 6e Chapter 8 Hard Drives.
Chapter 8 Supporting Hard Drives. 2 Objectives Learn about the technologies used inside a hard drive and how data is organized on the drive Learn how.
A+ Guide to Managing and Maintaining Your PC, 7e
Chapter Six Hard Drive Dr. Mohammad AlAhmad
Guide to Operating Systems, 5th Edition
Chapter Objectives In this chapter, you will learn:
AIC/XTORE SAS OVERVIEW
Enterprise Computing Applications
A+ Guide to Hardware: Managing, Maintaining, and Troubleshooting, 5e
A+ Breakout Ralph D Nyberg
Computer Hardware By Millie Hay.
Computer Hard Drive.
Hardware.
Computer hardware f1031 – computer hardware.
Hardware: Cables & Connectors
Inside the computer.
PC Maintenance and Repair
بداية الحاسب الشخصي ما هو الفرق بين "كمبيوتر IBM " و " كمبيوتر متوافق مع IBM " في الواقع لا شئ لماذا ‍‍‍‍‍!!!!؟؟؟‍‍‍‍‍‍‍ ‍‍‍ في عام 1981 طرحت شركة.
Direct Attached Storage and Introduction to SCSI
Mr C Johnston ICT Teacher
What’s in the Box?.
Storage Forensics Anatomy of a Hard Drive
Chapter 5 Supporting Hard Drives
1.00 Examine the role of hardware and software.
Hard Drives & RAID PM Video 10:28
Hard Drive Components 1.5 Install and configure storage devices and use appropriate media YT Video 3:30.
A Look at Computer Parts
Presentation transcript:

Forensics Forensic Acquisition

Forensic Acquisition SATA write blocker by Tableau Molex Power In SATA data connection External Power USB Firewire 800 SATA Power Out Firewire 400

Forensic Acquisition The fundamental connections are power and data. If it doesn’t work verify these connections first. External power

Forensic Acquisition Molex to SATA Power

Forensic Acquisition SATA data connection

Forensic Acquisition USB to computer data connection

Forensic Acquisition Write Blocking Active

Forensic Acquisition SATA Power Connector SATA Data Connector

Forensic Acquisition Different storage technologies require different equipment to image Hard Disk Drives (HDD’s). SATA (Serial ATA) IDE/PATA (Parallel ATA) USB for external storage SD/Compact Flash etc. SCSI/SAS

Forensic Acquisition PATA may be one of the most tortured terms in computers. Originally, the AT form factor (350mm x 305mm) motherboard used by IBM and IBM Clone PC’s. ATA, named from the AT Attachment for hard drives: a forty conductor ribbon with standard IBM .1” spacing used on MODU connectors. This was later retroactively named PATA to distinguish it from Serial ATA. © Dr. D. Kall Loper, all rights reserved

Forensic Acquisition IDE Ribbon Cable, 40 Connectors No copyright claim to image. Used under Fair Use.

Forensic Acquisition PATA, 1.8” and ZIF sled IDE Ribbon Cable MOLEX Power Connector Sled Adaptor for ZIF and 1.8” HDD’s Sled Inserts to 2.5” Male Pins 2.5” IDE Female pins for 2.5” IDE HDD’s

Forensic Acquisition PATA, 1.8” and ZIF form factors IDE Ribbon Cable Adaptor 1.8” HDD’s ZIF Adaptors ZIF Insertion Point

Forensic Acquisition USB Flash Drive

Forensic Acquisition SD Card Write Blocker and Adaptors

Forensic Acquisition SCSI Data Connector MOLEX Power Connector

Forensic Acquisition SCSI Terminator SCA backplane to 50 pin SCSI Adaptor 68 pin VHDCI to 50 pin micro Centronix (Internal) – SCSI-1 or SCSI-2 68 pin VHDCI to 80 pinUltra4 SCSI

Forensic Acquisition Parallel Attached SCSI No copyright claim to image. Used under Fair Use.

Forensic Acquisition SAS - Serial Attached SCSI SATA is Open Here SATA No copyright claim to image. Used under Fair Use. SAS

Forensic Acquisition SAS - Serial Attached SCSI Infiniband (IB) currently comes in 3 speeds: 1x 2.5Gb/s, 4x 10Gb/s, and 8x 30Gb/s No copyright claim to image. Used under Fair Use. Internal SFF-8087 (4XIB) to single lane SAS connectors (four 1XIB’s) SFF-8470, External Connector (4XIB)

Forensic Acquisition SAS – Serial Attached SCSI SFF-8484, 4 lane on HBA Copyright Adaptec. Used under Fair Use. SFF-8470 SFF-8484 SAS 8482, 4 single lane SAS HBA Card (Host Bus Adapter)

Forensic Acquisition SAS – Serial Attached SCSI SAS 8482 SFF-8484 SFF-8484 4 Lane unified on backplane HBA Copyright Adaptec. Used under Fair Use. HBA SFF-8470 4 Lane unified for external SAS 8482 4 Lane with single lane connectors

Forensic Acquisition SSD – Solid State Drive NGFF SSD to SATA Slim SATA to SATA mSATA to SATA mSATA to 2.5” SATA form factor

Forensic Acquisition SSD’s mSATA SSD SATA mSATA

Forensic Acquisition Software Write-blocking Usually only used in *nix (Linux/Unix etc.) Mounts the subject drive in a “read-only” file system. Reboots can cause alteration of subject drive. Can be used in situations where hardware write block is not possible. Cheap and flexible

Forensic Acquisition Acquisition Software There are numerous software tools available for acquisitions. SMART EnCase FTK Imager dd Paladin (Macs) MacQuisition (Macs)

Forensic Acquisition Software Acquisition High Level

Forensic Acquisition FTK Imager is a software acquisition tool. You can download a free copy at http://www.accessdata.com/support

Forensic Acquisition

Forensic Acquisition

Forensic Acquisition

Forensic Acquisition

Forensic Acquisition Output Format Expert Witness Format (EWF) EWF-E01, EWF-Ex01, and EWF-S01) QCOW version 1, 2, 3 RAW (dd) VHD (Virtual Hard Disk) VMDK (Virtual Machine Disk) AFF (Advanced Forensic Format)

Forensic Acquisition

Forensic Acquisition

Forensic Acquisition