|
Mar 21
2011
|
Forensically capturing a conventional disk is straightforward: power down the system, attach the drive to a portable forensic unit using a protective write-blocking device, and then capture the device bit-for-bit. Since the drive is protected by a write blocking device, the drive is presumed completely intact. Non-conventional mass storage devices (e.g., “solid-state disks,” hereafter “SSD”) implement features that invalidate the presumptive efficacy of write-blockers. This has implications in both the government and corporate worlds.


