Directions: Follow the download step and then fully answer each of the questions.
First: Download a free-imaging tool and install it on your computer. Image a hard drive/USB drive/Media to
include the hash value. Provide a screenshot of your image or log file created once the image is completed.
After doing the above, answer/do the following questions/prompts:
Create a report of the media imaged that includes the screenshot, and specifically discusses the following:
Integrity of the evidence including a discussion regarding how you verified the integrity of the image created.
How did you verify that the imaging tool created the image? How would you test the tool prior to imaging the
media or device? Why would you use this technique to test the tool?
Discuss the search technique used for finding documents. Describe a search strategy for the image you
created that would find documents with the date “2020” on the device. Use this search strategy- how many
total documents are there?
Discuss comparison methods used to examine the media image. What comparisons would you make in the
image created to eliminate files without “2020” in them?
Here’s a video that provides an example of how to create an image with a free tool (FTK Imager), and then
examine it in Autopsy: https://www.youtube.com/watch?v=DoHe206G4ms
Here’s a great free tool also called FTK Imager:
Here’s a video that demonstrates the skills (imaging and then searching) using FTK Imager and Autopsy (free):
Autopsy download: https://www.autopsy.com/