What do people currently use to acquire data from a USB device in a forensically sounds manner? I'm having trouble getting OSs to mount these devices read only so I need a solid way of doing this.
Thanks!
If you use Encase there is a boot disk image available from their website that has USB drivers. Getting it to work is hit and miss depending on your USB drivers and the device you are trying to read.
The registry hack (for windows xp sp2) described here (
Thank you, Greg. I tested the windows option thoroughly and am satistied with the data's integrity.
I appreciate the help!