This presentation will discuss options for forensic imaging of computers and apply the best solution to the problem of imaging an entire building full of computers. The important peripheral issues regarding ePreservation such as best evidence, collection methods, time estimation, common problems, and efficiency choices are included. The final section provides specific instructions and references for creating and testing a custom bootable CD for rapid acquisition of large data collections.
Ryan Korzeb is a former Florida State Trooper with a B.S. in Computer Information Technology & Cybersecurity from UMUC. He presently works for Digital Trust as a forensic technician.