[sleuthkit-users] Basic methods for imaging OS X hard drive
Brought to you by:
carrier
|
From: Mr. D. J. H. <da...@ma...> - 2008-09-24 17:32:51
|
I am ready to do my first analysis on a MacBook Pro volume. Someone quit a job, erased their files, and stoled clients. I just want to show file histories and activity in a time line. What is the best way to image the drive on the MacBook? Is there a tool in the SleuthKit? I read everything I could and did not see a function in TSK to copy images. I do have FileSalvage from SubRosaSoft. I do not have any write- blocked firewire tool like the Wiebetech device. I want to be able to defend that I did not change anything on the drive. Can someone provide some suggestions? Thanks |