After acquiring and preserving the evidence, evidence should be analyzed. Forensic tools can usually take a partition or a disk image as input to work on images in live systems.
Why a forensics investigator should have complete understanding of File system?
Updated: Mar 21, 2020