Honeypots mailing list archives

Re: Free/Open Source Disk Imaging Tools


From: "William Salusky" <change () dmzs com>
Date: Thu, 6 Feb 2003 12:24:10 -0400

I do not recommend using partimage for acquiring forensic images, as it will miss slack space entirely. (great tool, 
just not for forensics)

I have been using rda (remote data acquisition) http://www.md5sa.com which will do inline md5 hashes of the source and 
destination image and generate reporting as well.

This is now included in the fire distribution as well.

W


Current thread: