dcfldd
dcfldd is an enhanced version of dd with features useful for
forensics and security. dd copies a file (from standard input
to standard output, by default) converting and formatting according to
the options supplied.
This utility only generates raw image files.
Features include:
- Useful features for forensic investigators:
- Hashing on-the-fly, dcfldd can hash the input data as it is
being transferred, helping to ensure data integrity. Supports multiple
hashes at once
- Progress bar of how much data has already been sent.
- Flexible disk wipes, dcfldd can be used to wipe disks
quickly and with a known pattern if desired
- Image/wipe Verify, dcfldd can verify that a target drive is
a bit-for-bit match of the specified input file or pattern
- Simultaneous output to more than one file/disk is possible
- Split output, dcfldd can split output to multiple files
with more configurability than the split command
- Piped output and logs, dcfldd can send all its log data and
output to commands as well as files natively
- Verify capability

Return
to Digital Forensics Home Page
Last Updated Sunday, February 05 2012 @ 12:38 PM EST |