0PricingLogin
Cyber Security Academy · Lesson

Disk Imaging and File System Forensics

Create forensic images with dd/FTK Imager, analyze FAT and NTFS file systems, recover deleted files.

Forensic Imaging Principles

Forensic imaging creates a bit-for-bit copy of storage media while preserving evidence integrity. The original evidence must never be modified — work from a write-blocked copy. Hash the original and copy to verify exact reproduction.

Write Blockers

Hardware write blockers physically prevent write commands from reaching evidence drives. Software write blockers (dc3dd, FTK Imager) prevent OS-level writes. Always use a write blocker before connecting evidence drives to prevent accidental evidence modification.

All lessons in this course

  1. Disk Imaging and File System Forensics
  2. Memory Acquisition and Volatility Framework
  3. Timeline Analysis and Artifact Correlation
  4. Network Forensics with Wireshark
← Back to Cyber Security Academy