-
using knoppix for forensic (serious question)
Hello;
Any assistance will be appreciated.
I have knoppix running from a cd. I'd like to image a IDE hd. I have 2 hds in the system. the one I want to image and a blank one. I'm a bit familiar with the dd utility to image a drive but I need a little hand holding.
If the drive is say a 40 gig hd and i know that only about 6 gigs are used can I image the drive to a blank hd of 10 gig? If so what are the step - commands etc.
will the dd tool also image deleted files and slack space?
Once I've created an image using the dd tool on the target drive I want to perform some tests (i.e. like recover deleted files - I have a tool to do this and intent to use Win2K with this tool against the imaged drive.) What do I have to do to make or unimage the hd or can I just perform the dd image from one drive to another?
I'm getting a bit lost now. But if there is a good url with this information (step by step) I'd be most appreciative. Otherwise someone with a bit of patience would help.
Thanks
-
Senior Member
registered user
If you're using Knoppix 3.2 then there is a tool called 'partimage' already included. You can find it here: Kmenu>System>partimage
This might be useful for what you wish to accomplish. It can image a drive but will not make an exact mirror, it only copys actual data. Here is the partimage web site:
http://www.partimage.org/
-
This is a good page for learning about forensics in Unix:
http://www.crazytrain.com/papers.html
At the bottom of the page is an article about using dd.
-
Senior Member
registered user
-
I don't think partimage is a good idea for forensics because it understands ext2 and other file systems and I believe it only backs up the data and not the empty space.
You're probably better off with dd, and piping that across the network if you must (but to a local hard drive would be better).
Make sure you boot with the "noswap" option, otherwise, Knoppix could try to use a swap partition it finds on the hard drive that you are responsible for protecting.
Similar Threads
-
By Shopro in forum General Support
Replies: 2
Last Post: 05-12-2004, 09:12 PM
-
By boris90210 in forum Tips and Tricks
Replies: 1
Last Post: 02-20-2004, 08:50 AM
-
By redss in forum Customising & Remastering
Replies: 3
Last Post: 01-07-2004, 06:42 AM
-
By mark1221 in forum Hdd Install / Debian / Apt
Replies: 2
Last Post: 11-01-2003, 10:32 PM
-
By reecegeorge in forum Customising & Remastering
Replies: 0
Last Post: 10-30-2003, 10:50 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

Yottamaster 4 Bay RAID Hard Drive Enclosure External 2.5" 3.5" SATA HDD USB3.0-B
$120.80

Acasis 40Gbps Thunderbolt 4/3 M.2 NVMe 4 Bay RAID SSD Enclosure
$254.15

🔥24TB RAID Storage OWC ThunderBay 4, 4-Bay Thunderbolt 3 RAID 5 Array EXCELLENT
$788.88

G-Technology G-Raid 6TB External Hard Drive Array 0G01975 USB2 Firewire eSATA
$44.99

Orico 5Bay RAID USB3.0 External Hard Drive Enclosure 2.5/3.5 SATA HDD 80TB DAS
$130.04

OWC Mercury Elite Pro Dual USB-C 8 TB 2 Bay RAID Enclosure OWCMEDCH7T00
$99.99

LSI MegaRAID 9361-8i 12Gbps PCIe 3 x8 SATA SAS 3 8 Port RAID + BBU & CacheVault
$79.00

Dell PERC H740P 8GB Mini RAID Controller 12GBPs 5FMY4
$50.00

HP Smart Array P408i-P SR Gen10 12Gb PCIex8 SAS RAID Controller P/N: 836269-001
$74.99

LSI MegaRAID 9361-8i 8-Port 12Gbps PCIe 3.0 SAS/SATA Raid Controller 1GB Cache
$80.99