Windows Forensics Cookbook
上QQ阅读APP看书,第一时间看更新

How it works...

FTK Imager uses the physical drive of your choice as the source and creates a bit-by-bit image of it in EnCase's Evidence File format. During the verification process, MD5 and SHA1 hashes of the image and the source are compared.