Solved

What is the most stable/best software to create a forensic image of a server?

Posted on 2014-12-23
10
526 Views
Last Modified: 2015-01-19
I have a client who need me to create a forensic image of one of their servers. Unfortunately, the server that I am imaging  has a RAID Volume that has a 7TB partition with almost 5TB of data. I am attempting to image to a NAS device that we have onsite. Tools I have used up to this point seem to crash part of the way through.
0
Comment
Question by:PROACTIVETG
  • 5
  • 2
  • 2
  • +1
10 Comments
 
LVL 62

Expert Comment

by:btan
ID: 40514974
Encase and FTK can be one option to explore but the software based cloning of huge TB and storing live into NAS can be slow and prone to network disturbance. I was thinking if using dd for bit copy and cross cable to NAS (or a physically  accessible staging store to be later pump over to NAS backup) in simplistic baseline be more stable and faster instead of over the wire across network.

But this article stated various means to acquire RAID server though it did not drill further but concluded and eventually concluded it is still viable with with the gigabit NIC in the target server to be cloned. The time taken is not impressive but definitely faster across the network and will get the job done.

There may be newer evolution schemes (or existing) that use image splitting since creating a large single case raw data dump is not filesystem performance friendly. FTKimager is another tool which the article shed steps in imaging that include specifying fragment size of image split. which we can hear from more experts too.

Overall, I perceive for stable cloning, direct may be better compared to dedicated n/w but restrictive in use case where physical access is not viable. However, forensic tool cloning coverage objective leans more towards cloning with integrity intact from source to destination and the remaining external factors and dependencies causing n/w errors tampering the data are beyond the tool control. A separate logical LAN for such cloning is preferred and during off peak, but it quite a hassle and probable direct will be more quicker as shared in the articles.
0
 
LVL 9

Expert Comment

by:Carlos Ijalba
ID: 40516132
One of the fastest drive cloning/backup software tools I have used is Drive Snapshot:

http://www.drivesnapshot.de/en/

Compatible with all Windows file systems (FAT16, FAT32, NTFS,ReFS), Supports Linux EXT2/3/4/Reiser/XFS, and compatible with all Windows RAID Methods, It can split the image file in different sizes to avoid storage destination problems.

But all this is just in case the server is running Windows.
0
 
LVL 46

Expert Comment

by:noxcho
ID: 40516138
Try Hard Disk Manager 15 Server Basic: www.paragon-software.com from its Boot CD.
What is the reason they want to take forensic image? Is this for court or are they meaning EXACT image by forensic?
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 
LVL 62

Expert Comment

by:btan
ID: 40516196
Casper is another potential candidate that support hardware RAID arrays and does verification on copy (Automatic Copy Verification) and also is able to resume clone if there are disruption (SmartResume).
http://www.fssdev.com/products/casper/specifications.aspx
 Note for support  of Windows Server 2008/2003, it is Casper Server Edition while the client based OS likw Windows 7/8 etc is its Tech Edition. Here is the matrix comparison http://www.fssdev.com/products/casper/productmatrix.aspx
0
 

Author Comment

by:PROACTIVETG
ID: 40516443
The image i need to create is for court, not just a backup.
0
 
LVL 62

Expert Comment

by:btan
ID: 40516461
encase and ftk are recognised. importantly, it is maintaining the chain of custody of the evidence to be submitted. As long it is verifiable proof with high integrity against tamper data, it is legally still valid. It should not be tool driven (as much as I hope so). To clarify for Casper, it does clone drive image (SmartClone, AccuClone) and not just backup
0
 

Author Comment

by:PROACTIVETG
ID: 40516466
Thanks. Would I be able to take an image using Casper and use one of the other forensic programs to seasrch through image? Meaning Does Casper create images in any of these formats IMG, DD, ISO,BIN, 000,001,NRG,SDI,AFF,AFD,AMF,.E01,S01 ?
0
 
LVL 62

Expert Comment

by:btan
ID: 40516481
Casper does bit copy however the img is direct copy to the destined drive e.g.
Casper can be instructed to clone the entire contents of one hard disk to another hard disk, or clone a specific partition/volume to another partition/volume. When using the Copy an entire hard disk method, Casper completely replaces the existing content of the destination device, master boot record, existing partition structure, etc.
so to get the img then encase and ftkimager may be more prefered.
0
 
LVL 46

Expert Comment

by:noxcho
ID: 40516588
For the court you need a spftware which is officially certified. First check in court or by lawer if there is any of such imaging software which is officially recognized and accepted.
As for the search - you can take backup with Paragon, mount the image using Windows Disk Manager as the image is in vhd or vmdk format. Then use Windows search.
0
 
LVL 62

Accepted Solution

by:
btan earned 500 total points
ID: 40517218
if you take a look at this pdf from US DoJ, the case study stated the use of encase used by enforcement forensic investigator for imaging and also chain of custody (do see chapter 3 on Evidence acquisition that depicted the steps ) required for all admissible  evidence (proof authenticity from original author to holder)
https://www.ncjrs.gov/pdffiles1/nij/199408.pdf

one key point of acquisition is also that a write blocker capable tool or software is required such that the process will not taint the original evidence. The govt lab stated Forensicsoft SAFE (e.g.The Windows boot disk contains advance software write blocking technology that will block hardware RAID. This allows investigators to image the entire RAID volume at once.)
http://www.dfcsc.uri.edu/research/boot and http://www.forensicsoft.com/safe_compare_chart.php
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

this article is a guided solution for most of the common server issues in server hardware tasks we are facing in our routine job works. the topics in the following article covered are, 1) dell hardware raidlevel (Perc) 2) adding HDD 3) how t…
Create your own, high-performance VM backup appliance by installing NAKIVO Backup & Replication directly onto a Synology NAS!
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
This video teaches viewers how to encrypt an external drive that requires a password to read and edit the drive. All tasks are done in Disk Utility. Plug in the external drive you wish to encrypt: Make sure all previous data on the drive has been …

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question