SCI 4201 Practicals: Bethel Chaka N0161068D May 13, 2020
SCI 4201 Practicals: Bethel Chaka N0161068D May 13, 2020
1
1. You need to acquire an image of a disk on a computer that can’t
be removed from the scene, and you discover that it’s a Linux com-
puter. What are your options for acquiring the image? Write a brief
paper specifying the hardware and software you would use.
• Solution
Linux is the operating system that has some predefined features of the
forensics software related to data acquisition. One of the Linux’s features
is that it can access unmounted drives.
Linux Live CD’s unique feature is that it’s able to read and load most
drivers. Few tools are required to perform the data acquisition:
• A forensic Live CD
The best approach is to detach the hard drive, attach it via a hard-
ware write blocker to another device, and then grab a complete im-
age of it.That’s why you need to go with the Live CD route foren-
sics, but since it includes booting the device you might already cause
some firmware embedded code designed to alter / destroy potential
evidence (hard but not impossible to do, it depends on what sort of
criminal you are after).