Practical Digital Forensics: A Guide for Windows and Linux Users

Acquisition of Live Analysis and Volatile Data

Author(s): Akashdeep Bhardwaj*, Pradeep Singh* and Ajay Prasad *

Pp: 37-65 (29)

DOI: 10.2174/9789815305579124010005

* (Excluding Mailing and Handling)

Abstract

The process of conducting a proactive Forensic investigation begins with data acquisition. The process of obtaining Forensic data involves more than just moving files from one device to another. To generate a Forensic duplicate of the data, investigators use Forensic data acquisition to try and retrieve every bit of information from the victim system's memory and storage. Furthermore, the creation of this Forensic duplicate needs to ensure that the data's verifiable integrity is maintained and that it can potentially be used as evidence in court. The basic ideas of data acquisition are covered in this chapter, along with the several processes that make up the data acquisition methodology.


Keywords: Acquisition methodology, Data acquisition, Evidence integrity, Live analysis, Volatile data.

Related Journals
Related Books
© 2024 Bentham Science Publishers | Privacy Policy