Data imaging and maintaining evidence integrity
Imaging refers to the exact copying of data either as a file, folder, partition, or entire storage media or drive. When doing a regular copy of files and folders, not all files may be copied based on their attributes being set to the system or even hidden. To prevent files from being left out, we perform a special type of copy where every bit is copied or imaged exactly as it is on the current medium as if taking a picture or snapshot of the data.
Creating a copy of each bit of data exactly as is, is referred to as a physical or forensic image. Performing a bitstream copy ensures the integrity of the copy. To further prove this, hashing of the original evidence and the physical image is calculated and compared (which we will delve into shortly). If the forensic copy is off by even one bit of data, the hash values created by the respective algorithms will be quite different.
Tip
The original evidence should only be handled by...