April 13, 2023, 5:43 a.m. | /u/wrkacct17

Computer Forensics www.reddit.com

We have a customer who was hit by ransomware recently and hired a large computer forensics company to help figure out what happened. The forensics company told the customer's IT department to boot up the PCs, infected or not, and run a tool that will capture "live" EnCase E01 disk images and transmit to them via the web. I believe the app used was a variant or branded "FTK" which seems to be used everywhere in the industry. They said …

app boot capture cold computer computer forensics computerforensics customer department disk don drives forensics images industry large live pcs ransomware run software the web tool web workstation

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)