ProDiscover® IR was designed in a client/server model.Network Imaging & Analysis with ProDiscover® IR ProDiscover® can non-destructively look inside the HPA and image or extract any files from within.Removal is difficult and normally destroys access to the HPA’s file system (HPA becomes unallocated disk space).FirstWare and AREA-51 allow consumers to use HPA to hide data Copyright © 2003, Technology Pathways, LLC.Most imaging methods do not detect the presence of an HPA.Allows a disk to Hide an area of the disk for non-os use.Created in ATA 4 spec to allow manufactures to hide diagnostic & recovery tools.Unix “dd” Command – ProDiscover® supports reading dd images – ProDiscover® supports converting ProDiscover® image format to dd image format for use in other forensics tools Copyright © 2003, Technology Pathways, LLC.Hand Held Forensic Imagers – ICS – SoloForensics – LogiCube – SF-5000.Disk can be accessed via: – IDE Bus – USB-IDE Converters – Network (LAN/WAN) with (ProDiscover® IR) Copyright © 2003, Technology Pathways, LLC.ProDiscover® supports imaging local drives in several ways: – Disk-to-disk image (test booting) – Disk-to-image file (faster searches, disk geometry).NIST (National Institute of Standards & Technology) Disk Imaging Tool specifications #Prodiscover basic features software#
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |