Skip to content

Computer Forensics 101

Tools

WinHex, FTK, EnCase and SMART

Basic Process

1. Device is imaged using a tool. The image created is a clone with an exact bit-for-bit copy of the source device

2. Device is searched to collect items of interest and to recover data as needed