ABSTRACT

Now we begin the actual step-by-step process of making a bitstream image and collecting our forensic evidence from the disk of a computer. Our examples use MSDOS/Win95-98 as the operating system, but many of our procedures are the same for other operating systems.