Notifications
Clear all

setting up a lab

15 Posts
8 Users
0 Reactions
1,306 Views
(@psycho)
Active Member
Joined: 16 years ago
Posts: 14
Topic starter  

To clarify, by off site duplication I imply, one to many copying (usually such devices are not portable)


   
ReplyQuote
(@ba2llb)
Eminent Member
Joined: 16 years ago
Posts: 38
 

Memory acquisition should be done soonest, but as far as disk acquisition goes, I still don't see where you've differentiated between on-site and off-site acquisitions.

A production server that cannot be taken offline might necessitate a different procedure than a server that can be taken out of service even for a short time.


   
ReplyQuote
(@ddewildt)
Estimable Member
Joined: 17 years ago
Posts: 123
 

To clarify, by off site duplication I imply, one to many copying (usually such devices are not portable)

If you are looking for one to many copies look devices like the Logicube Dossier, ICS ImageMASSter Solo-4 Forensic and the Voom Hardcopy III. All of these have their own pros and cons, so I would recommend trying before purchasing. There are probably more on the market too, these are just the ones I can think of off the top of my head


   
ReplyQuote
BattleSpeed
(@battlespeed)
Eminent Member
Joined: 16 years ago
Posts: 36
 

Since either Encase or FTK will be overkill for "basic forensics" (as I understand the phrase), and since either one can handle those typical activities, it probably comes down to issues like cost, hardware requirements, availability of training and licensing provisions (relative to your business model) of the version you select. If it would be difficult to attend training in person, FTK provides live online training (for a fee). On the other hand, the (real) system requirements for running FTK are heftier, IMHO.

If you don't want to use free/very inexpensive tools, I'd go with X-ways Forensics from the standpoint of cost and system requirements, and add F-Response. The only downside (and in my view the primary failing of the company) is that training for X-Ways is inexplicably sparse here in the US. Why they haven't implemented a "train the trainer" program to rectify this glaring shortcoming is beyond me, but that doesn't detract from the value of the product.


   
ReplyQuote
(@patrick4n6)
Honorable Member
Joined: 16 years ago
Posts: 650
 

Raptor CD from Forward Discovery will do one to many onsite (2 destinations) and as a solution, it's both portable and cheap (free).


   
ReplyQuote
Page 2 / 2
Share: