Difference between revisions of "Dcfldd"

From ForensicsWiki
Jump to: navigation, search
m (Category.)
m (Category: GPL.)
Line 4: Line 4:
 
   os = [[Linux]], [[Windows]] |
 
   os = [[Linux]], [[Windows]] |
 
   genre = [[Category:Disk imaging]][[:Category:Disk imaging|Disk imaging]] |
 
   genre = [[Category:Disk imaging]][[:Category:Disk imaging|Disk imaging]] |
   license = [[GPL]] |
+
   license = [[Category:GPL]][[:Category:GPL|GPL]] |
 
   website = [http://dcfldd.sourceforge.net/ dcfldd.sf.net] |
 
   website = [http://dcfldd.sourceforge.net/ dcfldd.sf.net] |
 
}}
 
}}

Revision as of 14:28, 23 April 2006

dcfldd
Maintainer: Nicholas Harbour
OS: Linux, Windows
Genre: Disk imaging
License: GPL
Website: dcfldd.sf.net

dcfldd is an enhanced version of GNU dd. It has some useful features for forensic investigators:

  • On-the-fly hashing of the transmitted data.
  • Progress bar of how much data has already been sent.
  • Wiping of disks with known patterns.
  • Verification that the image is identical to the original drive, bit-for-bit.
  • Simultaneous output to more than one file/disk is possible.
  • The output can be splitted into multiple files.
  • Logs and data can be piped into external applications.