Hardware & software
Data acquisition, particularly preserving volatile data, will be foremost in the mind of the digital forensics investigator upon arrival at the scene of the incident.
If the machines are running, and particularly if the machines must not be shut down to maintain the core business function, volatile information, such as the contents of RAM, USB drives are important for capturing information live machines. To image RAM on a Windows machine, the USB drives should contain WinEn. WinAcq should be included for a live Windows acquisition, and MacLockPick for acquiring data from live Macintosh and Linux platforms (Bunting, 2012, p. 96). …show more content…
16). If resources allow, a spare response computer is suggested (Bunting, 2012, p. 96). A hardware disk imager is recommended (Gogolin, 2012, p. 16); although disk imaging capabilities are also present in certain forensic software (see below). A hardware write-blocker is recommended; although, software write-blockers are also available (see e.g., Lyle,