Difference between revisions of "Dcfldd"

From ForensicsWiki
Jump to: navigation, search
m
(Changed author name)
Line 1: Line 1:
 
{{Infobox_Software |
 
{{Infobox_Software |
 
   name = dcfldd |
 
   name = dcfldd |
   maintainer = [[Nicholas Harbour]] |
+
   maintainer = [[Nick Harbour]] |
 
   os = {{Linux}}, {{Windows}} |
 
   os = {{Linux}}, {{Windows}} |
 
   genre = {{Disk imaging}} |
 
   genre = {{Disk imaging}} |
Line 8: Line 8:
 
}}
 
}}
  
'''dcfldd''' is an enhanced version of [[GNU]] [[dd]]. It has some useful features for forensic [[investigator]]s:
+
'''dcfldd''' is an enhanced version of [[dd]]. It has some useful features for forensic [[investigator]]s:
  
 
* On-the-fly [[hash]]ing of the transmitted data.
 
* On-the-fly [[hash]]ing of the transmitted data.

Revision as of 16:00, 27 February 2007

dcfldd
Maintainer: Nick Harbour
OS: Linux,Windows
Genre: Disk imaging
License: GPL
Website: dcfldd.sf.net

dcfldd is an enhanced version of dd. It has some useful features for forensic investigators:

  • On-the-fly hashing of the transmitted data.
  • Progress bar of how much data has already been sent.
  • Wiping of disks with known patterns.
  • Verification that the image is identical to the original drive, bit-for-bit.
  • Simultaneous output to more than one file/disk is possible.
  • The output can be splitted into multiple files.
  • Logs and data can be piped into external applications.