Friday, June 5, 2015

Forensic Imaging and their Formats - Encase Image (E01)

Forensics imaging is the process of making an exact copy of a hard drive and or some other type of media. During the process, every 0 and 1 on the original disk/media is copied to the target disk/media. Prior to performing imaging, the destination drive must be zeroed or blanked (whereismydata.wordpress.com, 2009). 

The E01 extension is primarily used by Encase Forensic Imager. However, this format can also be found in tools such as FTK Imager. The image below shows part of the process of an image being acquired in E01 format in FTK Imager.



No comments:

Post a Comment