Forensics and Law Enforcement
From Just Solve the File Format Problem
(Difference between revisions)
Dan Tobias (Talk | contribs) |
|||
Line 8: | Line 8: | ||
* [[Advanced Forensics Format]] (AFF) | * [[Advanced Forensics Format]] (AFF) | ||
+ | * [[ANSI 378]] (used to store minutae of fingerprints) | ||
* [[ANSI 381]] (used to store images of fingerprints) | * [[ANSI 381]] (used to store images of fingerprints) | ||
* [[Digital Evidence Bag]] (DEB) | * [[Digital Evidence Bag]] (DEB) | ||
* [[EnCase hash map]] (Expert Witness) | * [[EnCase hash map]] (Expert Witness) | ||
+ | * [[WSQ]] (used to store images of fingerprints) | ||
See also [[Law]] | See also [[Law]] |
Revision as of 05:26, 26 May 2020
In the course of investigations, detectives sometimes need to preserve digital information. These are formats used in this process. See also Disk Image Formats. In contrast to those raw disk images, forensic formats also store various metadata as well as hash tables to track the origin of data and ensure it is not altered after the fact.
- Advanced Forensics Format (AFF)
- ANSI 378 (used to store minutae of fingerprints)
- ANSI 381 (used to store images of fingerprints)
- Digital Evidence Bag (DEB)
- EnCase hash map (Expert Witness)
- WSQ (used to store images of fingerprints)
See also Law
Links
- ShmooCon 2014 - You Don't Have the Evidence (January 2014) (video)
- The Sleuth Kit and Autopsy can read raw, Expert Witness, and AFF formats
- Is AFF the best choice for digital preservationists who create images?