ForensicsWiki will continue to operate as it has before and will not be shutting down. Thank you for your continued support of ForensicsWiki.

Difference between revisions of "Dcfldd"

From ForensicsWiki
Jump to: navigation, search
m
m
Line 2: Line 2:
 
   name = dcfldd |
 
   name = dcfldd |
 
   maintainer = [[Nicholas Harbour]] |
 
   maintainer = [[Nicholas Harbour]] |
   os = [[Category:Linux]][[:Category:Linux|Linux]], [[Category:Windows]][[:Category:Windows|Windows]] |
+
   os = {{Linux}}, {{Windows}} |
 
   genre = [[Category:Disk imaging]][[:Category:Disk imaging|Disk imaging]] |
 
   genre = [[Category:Disk imaging]][[:Category:Disk imaging|Disk imaging]] |
 
   license = [[Category:GPL]][[:Category:GPL|GPL]] |
 
   license = [[Category:GPL]][[:Category:GPL|GPL]] |

Revision as of 15:38, 6 May 2006

dcfldd
Maintainer: Nicholas Harbour
OS: Linux,Windows
Genre: Disk imaging
License: GPL
Website: dcfldd.sf.net

dcfldd is an enhanced version of GNU dd. It has some useful features for forensic investigators:

  • On-the-fly hashing of the transmitted data.
  • Progress bar of how much data has already been sent.
  • Wiping of disks with known patterns.
  • Verification that the image is identical to the original drive, bit-for-bit.
  • Simultaneous output to more than one file/disk is possible.
  • The output can be splitted into multiple files.
  • Logs and data can be piped into external applications.