Initial Respose Unit 2
Initial Respose Unit 2
Initial Respose Unit 2
FORENSIC DUPLICATION
INITIAL RESPONSE
• One of the first steps of any preliminary investigation is
to obtain enough information to determine an
appropriate response.
• F.R.E. §1001
If data are stored in a computer or similar device, any
printout or other output readable by sight, shown to
reflect the data accurately, is an "original".
• Federal Rules of Evidence § 1003
A duplicate is admissible to the same extent as
an original unless (1) a genuine question is
raised to the authenticity of the original or (2)
in the circumstances it would be unfair to
admit the duplicate in lieu of the original.
• For eg: sector-to sector copy of file from source hard drive to
destination hard drive.
• One tool, dd, is part of the GNU software suite. This was
improved upon by programmers at the DoD Computer
Forensics Lab and re-released as dcfldd. The command-line
parameters for dd and dcfldd are nearly identical, and the
core data transfer code has not been altered. If your team has
validated the operation of dd, very little work will be required
to validate the new features.