Acquisition
Techniques:
Electronic data is fragile by nature and can be easily
altered or erased if certain rules are not followed. For
example, just booting a computer into a Windows environment
will alter critical date stamps, erase temporary files and
cause numerous writes to the disk drive.
Specialized computer forensic software ensures that the
data on the subject computer hard drive is not altered in
any way during the acquisition process.
After initiation of the special boot-up procedure, the
examiner utilizes special computer forensic software to
create a bit-stream image, which is an exact "snap-shot" of
the subject hard drive.
This image is a complete non-invasive, sector-by-sector
copy of all data contained on the subject hard drive which
includes the recovery of all active, deleted and otherwise
unallocated data including that hidden in bad sectors &
clusters.
This process allows the investigator to "freeze time"
by saving a complete snapshot of the subject drive at the
time of acquisition.
Note:
Our forensic acquisition service is also useful, even
if there is no wrong-doing on the part of the
subject, since often an employee has files on
his or her 'vanished' hard drive that are found to be in
need several months after leaving the company.