Introduction
- Use forensic workstation and FTK Imager to image CDs, DVDs, and Blu-ray discs.
- This workflow should produce a .iso and .cue file for each evidence item.
- If disc will not mount or FTK Imager produces errors, switch to BitCurator workstation and Guymager.
- CD-Digital Audio (CD-DA) discs require additional testing and analysis. Alternative methods may be required to ensure long-term preservation.
Insert optical disc into disc drive
- Coming soon.
Launch FTK Imager and initiate "Create Disk Image..." process
- Launch FTK Imager.
- Click on "File" menu and select "Create Disk Image..."
- Select "Logical Drive" from the "Select Source" window and click on the "Next" button.
- Select the correct drive from the "Select Drive" window and click on the "Next" button.
- Review "Create Image" window. Ensure the "Verify images after they are created" and "Create directory listings..." boxes are checked.
- Click on the "Add..." button to open a "Select Image Destination" window.
- Click on the "Browse" button to open a "Browse for Folder" window. Browse to the DATA (D:) drive and select the destination folder for the image. Click on the "OK" button to make the selection.
- Provide an image filename (excluding extension). Whenever possible, use the Evidence ID recorded in the register of digital storage devices. Click on the "Finish" button.
If necessary, repeat steps 3-6 to create a copy of the image. Complete the "Select Image Destination" window. - Review the "Create Image" window. If settings are correct, click on the "Start" button to initiate the imaging process.
- Monitor the "Creating Image" windows. Optical discs should take less than 10 minutes to image and progress is usually demonstrated in the first minute.
- If images are successfully created, close pop-up windows.
- Open Windows Explorer and navigate to the DATA (D:\) drive. Confirm the following organization of data:
- D:\DATA
- Fonds/Collection
- Accession folder
- Evidence
- EvidenceID
- Evidence – copies
- EvidenceID_copy
- EvidenceID_copy
- Evidence
- Accession folder
- Fonds/Collection
- D:\DATA
- If progress stalls, close FTK Imager and try again. If FTK Imager is still unable to create images, stop the work and notify the Digital Archivist.
- Eject optical disc from forensic workstation.
- Return disc to appropriate born digital box.
Update register of digital storage devices
- Log into MyDal and navigate to University Archives' SharePoint site.
- Navigate to the "Register of digital storage devices" SharePoint list.
- Navigate to entry for applicable optical disc. Browse or use filters to locate the item.
- Click on "Edit" button to open record for editing.
- Add information about forensic imaging.
- Update other parts of entry as necessary.
- Click on "Save" button to save the edits.
Next steps
See procedures for creating a case in Forensic Toolkit (FTK).