Difference between revisions of "Dcfldd"

From ForensicsWiki
Jump to: navigation, search
 
m (typo in sourcedrive)
 
(13 intermediate revisions by 4 users not shown)
Line 1: Line 1:
(From the dcfldd documentation at http://dcfldd.sourceforge.net/)
+
{{Infobox_Software |
 +
  name = dcfldd |
 +
  maintainer = [[Nick Harbour]] |
 +
  os = {{Linux}}, {{Windows}} |
 +
  genre = {{Disk imaging}} |
 +
  license = {{GPL}} |
 +
  website = [http://dcfldd.sourceforge.net/ dcfldd.sf.net] |
 +
}}
  
dcfldd is an enhanced version of GNU dd with features useful for forensics and security. Based on the dd program found in the GNU Coreutils package, dcfldd has the following additional features:
+
'''dcfldd''' is an enhanced version of [[dd]] developed by the U.S. Department of [[Defense Computer Forensics Lab]]. It has some useful features for forensic [[investigator]]s such as:
  
* Hashing on-the-fly - dcfldd can hash the input data as it is being transferred, helping to ensure data integrity.
+
* On-the-fly [[hash]]ing of the transmitted data.
* Status output - dcfldd can update the user of its progress in terms of the amount of data transferred and how much longer operation will take.
+
* Progress bar of how much data has already been sent.
* Flexible disk wipes - dcfldd can be used to wipe disks quickly and with a known pattern if desired.
+
* Wiping of disks with known patterns.
* Image/wipe Verify - dcfldd can verify that a target drive is a bit-for-bit match of the specified input file or pattern.
+
* Verification that the image is identical to the original drive, bit-for-bit.
* Multiple outputs - dcfldd can output to multiple files or disks at the same time.
+
* Simultaneous output to more than one file/disk is possible.
* Split output - dcfldd can split output to multiple files with more configurability than the split command.
+
* The output can be split into multiple files.
* Piped output and logs - dcfldd can send all its log data and output to commands as well as files natively.
+
* Logs and data can be piped into external applications.
 +
 
 +
The program only produces [[raw image file|raw image files]].
 +
 
 +
==Example==
 +
'''Unix/Linux'''
 +
dcfldd if=/dev/sourcedrive hash=md5,sha256 hashwindow=10G md5log=md5.txt sha256log=sha256.txt \
 +
        hashconv=after bs=512 conv=noerror,sync split=10G splitformat=aa of=driveimage.dd
 +
This command will read ten Gigabytes from the source drive and write that to a file called driveimage.dd.aa.  It will also calculate the [[MD5]] hash and the sha256 hash of the ten Gigabyte chunk.  It will then read the next ten gigs and name that driveimage.dd.ab.  The md5 hashes will be stored in a file called md5.txt and the sha256 hashes will be stored in a file called sha256.txt.  The block size for transferring has been set to 512 bytes, and in the event of read errors, dcfldd will write zeros.

Latest revision as of 19:08, 19 June 2011

dcfldd
Maintainer: Nick Harbour
OS: Linux,Windows
Genre: Disk imaging
License: GPL
Website: dcfldd.sf.net

dcfldd is an enhanced version of dd developed by the U.S. Department of Defense Computer Forensics Lab. It has some useful features for forensic investigators such as:

  • On-the-fly hashing of the transmitted data.
  • Progress bar of how much data has already been sent.
  • Wiping of disks with known patterns.
  • Verification that the image is identical to the original drive, bit-for-bit.
  • Simultaneous output to more than one file/disk is possible.
  • The output can be split into multiple files.
  • Logs and data can be piped into external applications.

The program only produces raw image files.

Example

Unix/Linux

dcfldd if=/dev/sourcedrive hash=md5,sha256 hashwindow=10G md5log=md5.txt sha256log=sha256.txt \
       hashconv=after bs=512 conv=noerror,sync split=10G splitformat=aa of=driveimage.dd

This command will read ten Gigabytes from the source drive and write that to a file called driveimage.dd.aa. It will also calculate the MD5 hash and the sha256 hash of the ten Gigabyte chunk. It will then read the next ten gigs and name that driveimage.dd.ab. The md5 hashes will be stored in a file called md5.txt and the sha256 hashes will be stored in a file called sha256.txt. The block size for transferring has been set to 512 bytes, and in the event of read errors, dcfldd will write zeros.