In case of a live system, you will need to do the following:
However, in some situations, you will also need to image the hard drive without switching the system off. An example is in case the system is a server that is hosting a critical service that cannot be taken down, or there is an encryption present in the system, which will be reactivated if the system is powered off. This is why live acquisition is the preferred choice all the time.
In this section, we will use the FTK imager in imaging the hard drive of the live target ...
No credit card required