Authoritative Guide on Collecting Data from a Hard Drive with EnCase
For a good guide on how to collect data from a hard drive in a manner that is defensible under Minnesota state law, see Novacheck, Mary T.; Thornton, Molly B.; Beard, Jeffrey J.; and Burns, Mark (2014) "IT Technologies and How to Preserve ESI Cost Effectively," William Mitchell Law Review: Vol. 40: Iss. 2, Article 6, available at: http://open.mitchellhamline.edu/wmlr/vol40/iss2/6. See Appendix A, 'Sample Technologies for Preservation and Collection - Hard Drives'. The guide shows how data can be collected with EnCase. The authors are a partner at Bowman and Brooke LLP, a partner at Dorsey & Whitney LLP, an information governance consultant for IBM, an e-discovery manager for Boston Scientific, and a manager with KPMG's Forensic Technology Services practices.
Follow these basic steps:
1. First document each step in the process with a checklist.
![](https://static.wixstatic.com/media/af7fa4_524b015ae2f94e95be2aa89259e793f9~mv2.png/v1/fill/w_49,h_28,al_c,q_85,usm_0.66_1.00_0.01,blur_2,enc_auto/af7fa4_524b015ae2f94e95be2aa89259e793f9~mv2.png)
2. The hard drive of the source computer is extracted, connected to a write blocker, which is then in turn connected to the forensic expert's PC.
![](https://static.wixstatic.com/media/af7fa4_4db0cb67e9454af6b548da88b625f7d2~mv2.png/v1/fill/w_76,h_58,al_c,q_85,usm_0.66_1.00_0.01,blur_2,enc_auto/af7fa4_4db0cb67e9454af6b548da88b625f7d2~mv2.png)
3. EnCase allows for individual directories to be collected. When you're ready to proceed, click 'Acquire'.
![](https://static.wixstatic.com/media/af7fa4_18674ecf6cb64be38d1487101f6339f0~mv2.png/v1/fill/w_49,h_33,al_c,q_85,usm_0.66_1.00_0.01,blur_2,enc_auto/af7fa4_18674ecf6cb64be38d1487101f6339f0~mv2.png)
4. The paper recommends the following settings for the output. A file output from from EnCase will have a .E01 file extension. EnCase outputs data in 640 MB image files by default.
![](https://static.wixstatic.com/media/af7fa4_e914b9b588274733b69766c9ceb5f557~mv2.png/v1/fill/w_54,h_59,al_c,q_85,usm_0.66_1.00_0.01,blur_2,enc_auto/af7fa4_e914b9b588274733b69766c9ceb5f557~mv2.png)