Windows Forensics Cookbook
上QQ阅读APP看书,第一时间看更新

Windows Drive Acquisition

In this chapter, we will cover the following recipes:

  • Drive acquisition in E01 format with FTK Imager
  • Drive acquisition in RAW format with dc3dd
  • Mounting forensic images with Arsenal Image Mounter