Computer Forensics Tools & Techniques Catalog
Forensic Functionality:Disk Imaging
Description:No description available.
Technical Parameters: Tool host OS / runtime environment Supported evidence interfaces Supported target/destination interfaces Types of data that may be acquired Supported acquisition methods Supported image file formats Support for restoring the contents of an image file to a device Digest hash algorithms Data encryption
N/A N/A N/A N/A N/A N/A N/A N/A N/A
Windows host-dependent (software tool) host-dependent (software tool) whole drives/devices disk-to-disk copy (clone) raw (dd) image file restore supported CRC-32 Integrated support for data encryption
Mac OS IDE/PATA IDE/PATA partitions disk-to-file copy (image) Apple Disk Image (.dmg) support for restoring a subset of an image file MD5 No integrated support for data encryption
Linux SATA SATA user-defined sector range Logical EnCase Evidence File Format Version 2 (.ex01) image file restore unsupported SHA1
Custom boot environment (e.g., bootable Linux thumb drive/CD/DVD) SCSI SCSI Expert Witness (.e01) SHA2-256
Standalone device SAS SAS Expert Witness (.l01) SHA2-512
Standalone device (battery powered) PCIe PCIe Advanced Forensic Format (.aff) SHA3-256
Mini PCIe Mini PCIe ILook file format (.asb) SHA3-512
USB 2 USB 2 virtual disk format (e.g., .vdi, .vhd, .vmdk)
USB 3 (at native speeds) USB 3 (at native speeds) N/A
IEEE 1394 (FireWire) Thunderbolt
Thunderbolt CompactFlash
CompactFlash Ethernet
SD card
iSCSI (network)
Ethernet