DFRWS CDESF (Sep 1, 2006). Survey of Disk Image Storage Formats. 


After reviewing the article, decide which disk image storage format you think is the best. Explain your reasoning.  

Basing on Table 1: Matrix of file formats and the tools that support them, I think Encase is the best because it includes the Expert Witness format its predecessor and its supported by almost of forensic tools. As explained in the document the EnCase format is a closed format that is defined by Guidance Software for use in their EnCase tool to store hard drive images and individual files and has added new metadata to the original Expert Witness format. 

Encase is embedded with a variety of forensic functions that include attributes such as disc imaging and preservation, absolute data recovery in the form of the bit stream, etc. In this series of humongous applications, when Encase is used for creating backup (i.e. Imaging) of hard drives, CD, USB drive, etc., a file known as "E01" is produced. This ".e01" extension file is primarily recognized as "Encase Image File Format". 

The E01 image file format is also known as EWF (an acronym for Expert Witness Format). The concept of the E01 encase image developed by the Encase software came into existence as a result of efficient efforts by the Guidance Software to assist forensic investigators, analysts, and forensic scientists in finding an organized and systematized data for investigation ("Encase E01 File Format Explained — Disk Image Forensics", 2018). 

Though I think the iXImager format must be good and that’s why its restricted and used by only law enforcement and government. 

Sources: 
Encase E01 File Format Explained — Disk Image Forensics. (2018). Retrieved 27 May 2020, from http://www.forensicsware.com/blog/e01-file-format.html 

Comments

Popular posts from this blog

Chain of Custody - OJ Simpson case

File Carving or Data Carving

Privacy issues associated with data mining