Osfclone - Opened Upward Origin Utility To Practise Together With Clone Forensic Disk Images


OSFClone is a free, self-booting solution which enables y'all to exercise or clone exact raw disk images speedily in addition to independent of the installed operating system. In add-on to raw disk images, OSFClone also supports imaging drives to the opened upward Advance Forensics Format (AFF), AFF is an opened upward in addition to extensible format to shop disk images in addition to associated metadata, in addition to Expert Witness Compression Format (EWF). An opened upward measure enables investigators to speedily in addition to efficiently purpose their preferred tools for campaign analysis. After creating or cloning a disk image, y'all tin flame mountain the picture amongst PassMark OSFMount earlier conducting analysis amongst PassMark OSForensics™.


OSFClone creates a forensic picture of a disk, preserving whatever unused sectors, slack space, file fragmentation in addition to undeleted file records from the master copy difficult disk. Boot into OSFClone in addition to exercise disk clones of FAT, NTFS in addition to USB-connected drives! OSFClone tin flame hold upward booted from CD/DVD drives, or from USB flash drives.

OSFClone tin flame exercise disk images inwards the dc3dd format. The dc3dd format is ideal for reckoner forensics due to its increased marking of reporting for progress in addition to errors, in addition to might to hash files on-the-fly.

Verify that a disk clone is identical to the source drive, yesteryear using OSFClone to compare the MD5 or SHA1 hash betwixt the clone in addition to the source drive. After picture creation, y'all tin flame pick out from a arrive at of compression options to trim down the size of the newly created image, increasing portability in addition to saving disk space.


Use OSFClone to save forensic meta-data (such equally illustration number, bear witness number, examiner name, description in addition to checksum) for cloned or created images.