NETS1032

Capturing Forensics Images of Storage Devices

Introduction

This is the second module in the NETS1032 Digital Forensics course. It is expected to be completed in week 2 of the course, with the quiz due before the start of the next class. We cover the concepts and practice of capturing forensic images of storage devices in both Windows and Linux. You are required to have root access to a Linux system and Administrator access to a Windows PC for this. It is recommended to use either VMWare or VirtualBox for this, but you can also use any other solution you wish for this including installing these environments on physical computers, using another virtualization solution such as Parallels, or using cloud-based virtual computers such as those sold by Amazon. It is the student’s responsibility to obtain, install, and become familiar with these virtualization programs and operating environments as necessary. You are expected to be competent with the command line in both Windows and Linux.

For your lab work, ensure you have access to both a Linux desktop environment with root, and a Windows desktop with Administrator. You will be showing your work to the professor throughout the semester, so you will need to be able to share your lab system screen, and the lab system you use will need to be clearly identified as your own (you should use your own name for the login, or at least something unique to you). No marks will be given for showing work on a lab system which is not your own.

Learning Objectives

At the end of this lesson, students will:

These objectives are in support of Learning Outcomes 2 and 5 in the Course Outline.

To do List

Lesson Material

Learning Activity

Watch the videos from the presentation, as well as the videos listed under additional resources. Briefly review the materials available at the other websites listed under Additional Resources.

Do the Image Capture Assignment.

Additional Resources

Videos

General resources

Imaging Resources

Graded Activity

The lab instructions tell you what parts of the lab activity are graded, and when you need to be capturing screenshots during the lab.

Quiz

The quiz is found on Blackboard under Assignments and Tests.

Test

There is no separate test for this topic. The quiz will count for your testing mark in this topic.

Summary

In this module, you have been introduced to image capture. You should now be aware of:

Completing the quiz will provide you with a measure of your knowledge in these areas. For the next class you should have your computing environment available with access to both Linux and Windows.