![list features of prodiscover basic list features of prodiscover basic](https://media.cheggcdn.com/study/2bf/2bf36cff-5c74-4cdd-859a-e502b0d03d47/13104-2-5HOPEI1.png)
In many situations utilities are repurposed for the forensics process, such as graphics file recovery utilities and hex editors (the original forensics tool). Utility applications used in computer forensics may or may not be created specifically for forensics use. Applications in the Utility category are designed to perform a specific function, such as recover deleted files, remove the HPA of a disk, or create a disk image. In this category, applications are created specifically with computer forensics in mind and usually support all four phases of the computer forensics process: collection, preservation, filtering, and reporting. Tools in use can be split into two categories: Tier I-Forensics Application Suites, and Tier II-Utilities and Other.įorensics Application Suite (Tier I).
#LIST FEATURES OF PRODISCOVER BASIC SOFTWARE#
Software used for the collection and preservation of computer evidence usually falls into one of three broad categories: Forensics Application Suite, Utility, and Other.
![list features of prodiscover basic list features of prodiscover basic](https://genderi.org/list-digital-evidence-storage-formats/img36.jpg)
Physical Disk Interfaces and Access Methods.Understanding Windows Rootkits in Memory.Traditional Incident Response of Live Systems.Volatile Data in Routers and Appliances.Open Systems Interconnection (OSI) Model.Rules of Evidence, Case Law, and Regulation.Formalized Computer Forensics from the Start.Computer Forensics and Evidence Dynamics.Brown Computer Evidence: Collection and Preservation, Second Edition