Skip to content

Forensic Image

Definition

A bit-for-bit verified copy of a storage medium, created using a write-blocker to prevent modification of the original. The copy is verified against the original using a cryptographic hash (MD5 or SHA-256). All analysis is performed on the image, not the original device.

Creation method
Bit-by-bit copy using a write-blocker
Verification
Cryptographic hash (MD5 or SHA-256)
Analysis source
Always the image, never the original

Common questions

What is a forensic image?+

A forensic image is a bit-by-bit or bit-for-bit copy of a storage device or storage medium. It is created using a write-blocker to prevent any changes to the original, and verified using cryptographic hashing (MD5 or SHA-256) to confirm accuracy.

Why not just analyze the original device?+

Analysis is always performed on the image, never the original device. This keeps the original pristine and allows you to prove its integrity at any time during an investigation.

What formats can a forensic image use?+

Common formats include raw dd format, EnCase E01, and AFF4. Each is a verified container format designed for forensic work.

Related terms

Write Blocker
A hardware or software device interposed between a digital storage medium and the forensic workstation that prevents any write commands from reaching...
Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Order of Volatility
The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
ACPO Principles
Four principles for digital evidence handling published by the UK's Association of Chief Police Officers (now maintained by the Forensic Science Regulator):...
Authentication
The process of establishing that a document is what it purports to be. Under the US FRE Rule 901, the proponent must...
Best Evidence Rule
The principle, codified in FRE Rule 1002, that the original of a document is required to prove its content. Under Rule 1003,...
Chain of Custody Log
The continuous record documenting every person who accessed a digital exhibit, every transfer of possession, every examination action, and the hash values...
Cryptographic Hash (MD5/SHA-256)
A fixed-length digest computed from the contents of a file or disk image. Used to verify that a forensic copy is identical...
Custodian
In e-discovery, a person who possesses, controls, or has responsibility for documents or electronic records relevant to an investigation. Identifying custodians is...
Electronically Stored Information (ESI)
Any information created, stored, or transmitted in electronic form, including emails, database records, spreadsheets, accounting system logs, chat messages, and metadata. ESI...
ERP System
Enterprise Resource Planning software (SAP, Oracle, Microsoft Dynamics, and similar platforms) that manages financial and operational records. ERP databases are often the...
Failure Analysis
The forensic engineering discipline of determining the mechanism and cause of a structural, mechanical, or material failure, and assessing whether it resulted...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.