Live Imaging using FTK Imager on Windows OS Systems
While there are many different methods for disk imaging, one of them is performing this process on a running Windows operating system. During imaging on an active Windows system, there is a risk of unintentionally writing data to the disk. This can compromise the integrity of the data under investigation. Therefore, it is recommended that this method be avoided unless absolutely necessary.
Imaging with FTK Imager:
To perform imaging with the FTK Imager application, the application must be stored on a USB flash drive. After the computer to be imaged is powered on, the FTK Imager application on the USB drive is launched by double-clicking. The application interface that will then appear on the screen is as follows:
To image one of the disks on the computer where the application is running, click on the "File" tab in the top left corner, followed by "Add Evidence Item."
After clicking on the relevant section, the following screen will appear, where you decide whether the image will be taken physically or logically. Then, the disk to be imaged is selected.
Determining the Image Extension and Selecting the Destination for the Image:
Another important aspect of imaging is ensuring that the image is in a format suitable for analysis in EnCase after the process is complete. Therefore, it is crucial that the image has the E01 extension. After clicking the "Finish" button on the previous screen, you can make this selection on the screen that follows.
Similarly, the image details (such as the image number) and the destination where the image will be stored (target disk) are specified in this section.
Selecting the Compression Ratio:
Especially for images of very large disks, compression can reduce their size to some extent. This reduces the amount of space the image will occupy on the target disk, allowing more images to fit into the same target disk. The compression ratio is selected from the section below. However, it is important to note that a higher compression ratio may extend the imaging process.
After selecting the "Finish" option, the imaging process will begin as shown below.
Image Verification:
Yorumlar
Yorum Gönder