Abstract:
Disclosed herein are a logical imaging apparatus and method for digital forensic triage. The logical imaging method for digital forensic triage includes receiving files selected as a digital evidence target, creating a logical imaging file, inside of which is formatted in a predetermined file system structure, recording the selected files in accordance with the file system structure of the created logical imaging file, and storing selected file list information about a list of the recorded selected files, and creating a separate selected list information file and a separate logical imaging summary file outside the logical imaging file.
Abstract:
In a method for recovering a partition using backup boot record information, an unallocated area is separated from a disk or an evidence image. The unallocated area is searched for a location of a backup boot record. Whether is backup boot record of a file system to be detected is present in found sectors is analyzed. If the backup boot record is found to be the backup boot record of the file system desired to be detected as a result of the analysis, it is verified whether the backup boot record is a boot record of a valid partition. If it is verified that the backup boot record is the boot record of the valid partition, a file system of a deleted partition is parsed using the backup boot record and a deleted directory or file is recovered.
Abstract:
Disclosed herein are an evidence collection guidance method and apparatus for file selection. The evidence collection guidance method includes generating pieces of preliminary analysis information that are pieces of collection target information, setting levels of the pieces of preliminary analysis information based on predefined rules, and generating and outputting notification information including summary description information and follow-up measure items related to the pieces of preliminary analysis information corresponding to the levels.