Chapter 5: Evidence Acquisition and Preservation with dc3dd and Guymager
In the previous chapter, we learned that documentation and proper procedures are key in any investigation. These ensure the integrity of the investigation by providing proof of data authenticity and preservation of the original evidence and documentation, which can be used to achieve the same exact results if the usage of tools and methods are repeated.
In this chapter, we will demonstrate forensically sound techniques for the acquisition of data using bitstream copies, including creating data hashes, in keeping with best practices.
In this chapter, we will cover the following topics:
- Device identification in Linux
- Creating MD5 and SHA hashes
- Using dc3dd for data acquisition
- Erasing drives with dc3dd
- Using DD for data acquisition
- Using the Guymager GUI for data acquisition
The first tool we will use for acquisition is called Department of Defense Cyber Crime Center Data...