{"id":831,"date":"2020-09-30T12:40:09","date_gmt":"2020-09-30T11:40:09","guid":{"rendered":"https:\/\/cybercop-training.ch\/?p=831"},"modified":"2020-09-30T12:40:09","modified_gmt":"2020-09-30T11:40:09","slug":"disk-forensics-p7","status":"publish","type":"post","link":"https:\/\/cybercop-training.ch\/?p=831","title":{"rendered":"Disk Forensics P7"},"content":{"rendered":"<blockquote>\n<p dir=\"ltr\" style=\"text-align: justify;\">Image acquisition involves making a copy (or several copies) of the seized hard disk which can be then used to forensics analysis. This allows the investigators to analyze this image while ensuring the integrity and present condition of the real evidence disk.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\">In this lab, the evidence hard disk is mounted on \u2018\/dev\/sdc\u2019. The <a href=\"https:\/\/github.com\/libyal\/libewf\" target=\"_blank\" rel=\"noopener noreferrer\"><b>ewf-tools<\/b><\/a>\u00a0are installed on the lab machine. The tool uses the Expert Witness Compression Format (EWF).<\/p>\n<p dir=\"ltr\" style=\"text-align: justify;\"><b>Objective:<\/b>\u00a0Create a disk image for evidence hard disk using ewf-tools tools.<\/p>\n<\/blockquote>\n<p dir=\"ltr\">First I&#8217;ll check if the disk is mounted on the filesystem<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-834\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf1.png\" alt=\"\" width=\"400\" height=\"236\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf1.png 400w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf1-300x177.png 300w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><\/p>\n<p dir=\"ltr\">To prevent any failures during disk imaging, let&#8217;s unmount the disk first<\/p>\n<p dir=\"ltr\"><code>umount \/dev\/sdc<\/code><\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-836\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf2.png\" alt=\"\" width=\"408\" height=\"201\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf2.png 408w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf2-300x148.png 300w\" sizes=\"auto, (max-width: 408px) 100vw, 408px\" \/><\/a><\/p>\n<p dir=\"ltr\">Everything is prepared now to use ewfacquire to create a disk image<\/p>\n<p dir=\"ltr\"><code>ewfacquire \/dev\/sdc<\/code><\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-837\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf3.png\" alt=\"\" width=\"491\" height=\"326\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf3.png 491w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf3-300x199.png 300w\" sizes=\"auto, (max-width: 491px) 100vw, 491px\" \/><\/a><\/p>\n<p dir=\"ltr\">Further you can enter some more informations like Case Number, Description or Examiner name..<\/p>\n<p dir=\"ltr\">For all the other options I&#8217;ll leave the default values:<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-838\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf4.png\" alt=\"\" width=\"522\" height=\"325\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf4.png 522w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf4-300x187.png 300w\" sizes=\"auto, (max-width: 522px) 100vw, 522px\" \/><\/a><\/p>\n<p dir=\"ltr\">Let&#8217;s start the process:<\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-839\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf5.png\" alt=\"\" width=\"569\" height=\"320\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf5.png 569w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf5-300x169.png 300w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><\/a><\/p>\n<p dir=\"ltr\">To verify the disk image we can use the following command:<\/p>\n<p dir=\"ltr\"><code>ewfinfo evidence.E01<\/code><\/p>\n<p dir=\"ltr\"><a href=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-840\" src=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf6.png\" alt=\"\" width=\"515\" height=\"566\" srcset=\"https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf6.png 515w, https:\/\/cybercop-training.ch\/wp-content\/uploads\/2020\/09\/ewf6-273x300.png 273w\" sizes=\"auto, (max-width: 515px) 100vw, 515px\" \/><\/a><\/p>\n<p dir=\"ltr\">\n<p dir=\"ltr\">\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>Image acquisition involves making a copy (or several copies) of the seized hard disk which can be then used to forensics analysis. This allows the <a class=\"mh-excerpt-more\" href=\"https:\/\/cybercop-training.ch\/?p=831\" title=\"Disk Forensics P7\">[&#8230;]<\/a><\/p>\n<\/div>","protected":false},"author":2,"featured_media":832,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,16],"tags":[],"class_list":["post-831","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-forensic","category-linux"],"_links":{"self":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts\/831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=831"}],"version-history":[{"count":3,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts\/831\/revisions"}],"predecessor-version":[{"id":841,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/posts\/831\/revisions\/841"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=\/wp\/v2\/media\/832"}],"wp:attachment":[{"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybercop-training.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}