SID not found
Newbie here. We are doing a forensics on a portable hard drive and it shows connectivity of the hard drive to a computer system on a particular date but not the SID or computer name.
Is it possible that if a hardware lock was used with the hard disk to image the hard drive, no computer name or SID will show up ?
How can we find out more information from the forensic image about the computer system the hard disk was connected to ?
forensic clone is an exact, bit for bit copy of a hard drive. It's also known as a bit stream image. In other words, every bit (1 or 0) is duplicated on a separate, forensically clean piece of media, such as a hard drive. Why go to all that trouble? Why not just copy and paste the files? The reasons are significant. First, copying and pasting only gets the active data. That is, data that are accessible to the user. These are the files and folders that users interact with, such as a Microsoft Word document. Second, it does NOT get the data in the, including deleted and partially overwritten files. Third, it doesn't capture the file system data. All of this would result in an ineffective and incomplete forensic exam.