DIGITAL FORENSIC ACQUISITION KIT AND METHODS OF USE THEREOF
First Claim
1. An electronic forensics tool comprising:
- (a) a physical portable memory device, wherein said physical portable memory device is capable of connecting to a target device;
(b) a forensic acquisition script, wherein said forensic acquisition script is able to load onto said target device and analyze hardware and software configurations of said target device and copy physical memory from the target device to the physical portable memory device.
2 Assignments
0 Petitions
Accused Products
Abstract
Disclosed are compositions, methods, and kits, for issuing and conducting automated imaging and preservation for obtaining digital forensic data from active (i.e., powered-on) and non-active (i.e., powered-off) computer systems. In certain embodiments, the invention further encompasses providing a customer base a preliminary report of data. In other embodiments, the invention encompasses the option to receive a virtual machine file set of the acquired information for additional viewing and examination by the customer. The invention further encompasses methods and systems for implementing the embodiments of the invention. The invention also encompasses methods, apparatuses, and systems for secure forensic investigation of a target machine.
37 Citations
24 Claims
-
1. An electronic forensics tool comprising:
-
(a) a physical portable memory device, wherein said physical portable memory device is capable of connecting to a target device; (b) a forensic acquisition script, wherein said forensic acquisition script is able to load onto said target device and analyze hardware and software configurations of said target device and copy physical memory from the target device to the physical portable memory device. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. A method of obtaining forensic data from a target computer comprising:
-
a. connecting a physical portable memory device to a target device; and b. running a forensic acquisition script, wherein said forensic acquisition script is able to load onto said target device and analyze hardware and software configurations of said target device and copy physical memory from the target device to the physical portable memory device - View Dependent Claims (14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24)
-
Specification