Download presentation
Presentation is loading. Please wait.
1
Forensics Forensic Acquisition
2
Forensic Acquisition SATA write blocker by Tableau Molex Power In
SATA data connection External Power USB Firewire 800 SATA Power Out Firewire 400
3
Forensic Acquisition The fundamental connections are power and data.
If it doesn’t work verify these connections first. External power
4
Forensic Acquisition Molex to SATA Power
5
Forensic Acquisition SATA data connection
6
Forensic Acquisition USB to computer data connection
7
Forensic Acquisition Write Blocking Active
8
Forensic Acquisition SATA Power Connector SATA Data Connector
9
Forensic Acquisition Different storage technologies require different equipment to image Hard Disk Drives (HDD’s). SATA (Serial ATA) IDE/PATA (Parallel ATA) USB for external storage SD/Compact Flash etc. SCSI/SAS
10
Forensic Acquisition PATA may be one of the most tortured terms in computers. Originally, the AT form factor (350mm x 305mm) motherboard used by IBM and IBM Clone PC’s. ATA, named from the AT Attachment for hard drives: a forty conductor ribbon with standard IBM .1” spacing used on MODU connectors. This was later retroactively named PATA to distinguish it from Serial ATA. © Dr. D. Kall Loper, all rights reserved
11
Forensic Acquisition IDE Ribbon Cable, 40 Connectors
No copyright claim to image. Used under Fair Use.
12
Forensic Acquisition PATA, 1.8” and ZIF sled IDE Ribbon Cable
MOLEX Power Connector Sled Adaptor for ZIF and 1.8” HDD’s Sled Inserts to 2.5” Male Pins 2.5” IDE Female pins for 2.5” IDE HDD’s
13
Forensic Acquisition PATA, 1.8” and ZIF form factors IDE Ribbon Cable
Adaptor 1.8” HDD’s ZIF Adaptors ZIF Insertion Point
14
Forensic Acquisition USB Flash Drive
15
Forensic Acquisition SD Card Write Blocker and Adaptors
16
Forensic Acquisition SCSI Data Connector MOLEX Power Connector
17
Forensic Acquisition SCSI Terminator SCA backplane to 50 pin
SCSI Adaptor 68 pin VHDCI to 50 pin micro Centronix (Internal) – SCSI-1 or SCSI-2 68 pin VHDCI to 80 pinUltra4 SCSI
18
Forensic Acquisition Parallel Attached SCSI
No copyright claim to image. Used under Fair Use.
19
Forensic Acquisition SAS - Serial Attached SCSI SATA is Open Here SATA
No copyright claim to image. Used under Fair Use. SAS
20
Forensic Acquisition SAS - Serial Attached SCSI
Infiniband (IB) currently comes in 3 speeds: 1x 2.5Gb/s, 4x 10Gb/s, and 8x 30Gb/s No copyright claim to image. Used under Fair Use. Internal SFF-8087 (4XIB) to single lane SAS connectors (four 1XIB’s) SFF-8470, External Connector (4XIB)
21
Forensic Acquisition SAS – Serial Attached SCSI
SFF-8484, 4 lane on HBA Copyright Adaptec. Used under Fair Use. SFF-8470 SFF-8484 SAS 8482, 4 single lane SAS HBA Card (Host Bus Adapter)
22
Forensic Acquisition SAS – Serial Attached SCSI SAS 8482 SFF-8484
SFF Lane unified on backplane HBA Copyright Adaptec. Used under Fair Use. HBA SFF Lane unified for external SAS Lane with single lane connectors
23
Forensic Acquisition SSD – Solid State Drive NGFF SSD to SATA
Slim SATA to SATA mSATA to SATA mSATA to 2.5” SATA form factor
24
Forensic Acquisition SSD’s mSATA SSD SATA mSATA
25
Forensic Acquisition Software Write-blocking
Usually only used in *nix (Linux/Unix etc.) Mounts the subject drive in a “read-only” file system. Reboots can cause alteration of subject drive. Can be used in situations where hardware write block is not possible. Cheap and flexible
27
Forensic Acquisition Acquisition Software
There are numerous software tools available for acquisitions. SMART EnCase FTK Imager dd Paladin (Macs) MacQuisition (Macs)
28
Forensic Acquisition Software Acquisition High Level
29
Forensic Acquisition FTK Imager is a software acquisition tool. You can download a free copy at
30
Forensic Acquisition
31
Forensic Acquisition
32
Forensic Acquisition
33
Forensic Acquisition
34
Forensic Acquisition Output Format Expert Witness Format (EWF)
EWF-E01, EWF-Ex01, and EWF-S01) QCOW version 1, 2, 3 RAW (dd) VHD (Virtual Hard Disk) VMDK (Virtual Machine Disk) AFF (Advanced Forensic Format)
35
Forensic Acquisition
36
Forensic Acquisition
37
Forensic Acquisition
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.