Avsnitt Course 36 - Windows Forensics and Tools | Episode 2: Windows Forensic Imaging and Drive Nomenclature CyberCode Academy Spela Dela
In this lesson, you’ll learn about: Windows forensic imaging and data structure fundamentals1. What is Forensic Imaging? A bit-by-bit, sector-by-sector copy of a storage deviceCaptures everything, not just visible files 🔹 What it Includes Active files and foldersDeleted filesUnallocated spaceSlack space 👉 Key Difference: Not a backup → it is an exact forensic replica 2. Why Forensic Imaging Matters Preserves original evidencePrevents modification of:File timestampsMetadata 👉 Legal Importance: Required for court-admissible investigations 3. Physical vs Logical Drives (Windows Naming)🔹 Physical Drives Identified as:Disk 0Disk 1Represent actual hardware 🔹 Logical Drives Represent partitions using letters:C:D:E: 👉 Analogy: Physical disk → entire cabinetLogical drives → drawers inside the cabinet 🔹 Historical Note A: and B: reserved for floppy disks 4. File System Hierarchy🔹 Structure Levels Volume (highest level)PartitionDirectory (folder)File 🔹 File Definition A logical grouping of related data 👉 Key Insight: Understanding hierarchy helps in locating and analyzing evidence 5. Processes and Threads (Execution Basics) Process → running programThread → smallest execution unit within a process 👉 Why it matters: Helps track:Program executionMalicious activity 6. Data Integrity & Verification🔹 Hashing Concept Generate a unique fingerprint for data 🔹 Algorithm Example MD5 hash 🔹 Key Properties Same file → same hashRename file → hash unchangedChange 1 bit → completely different hash 👉 Use Case: Verify forensic image integrity 7. Chain of Trust in Forensics Acquire image → generate hashAnalyze copy → compare hash again 👉 Goal: Ensure no tampering occurred Key Takeaways Forensic imaging captures complete disk data, including hidden contentPhysical and logical drives represent different abstraction layersFile systems follow a structured hierarchyHashing ensures data integrity and authenticityEven a tiny change in data invalidates evidence Big PictureForensic imaging helps you:👉 Move from raw disk → verified evidence copyMental Model Disk → Image → Hash → Analyze → Verify You can listen and download our episodes for free on more than 10 different platforms:https://linktr.ee/cybercode_academy Rss Apple Podcaster →