Best software for bit-level disk imaging for use in forensics
Posted on 2005-04-27
If I wanted to make a bit-level, perfect image copy of a hard drive on a computer I suspect has been hacked or tampered with, which software would you guys recommend I use? Out of the many packages I've seen, most require you to remove the hard drive, and then connect it to a forensics PC, but doesn't the simple fact of turning off the suspected system go against evidence preservation? NO ONE here is a forensics expert, but if there is an incident, we would like to do a preliminary search to determine if an intrusion has ocurred, and if so, then we would call in the big guns, but of course this means we need to create a mirror image of the drive to work on and not disturb the original, for when the big pros are called in. What say you?