Getting started in Digital Forensics

A lot of people have asked how to get started with digital forensics. It’s great that so many people from so many different places are interested. There are many different paths available. To try to help aspiring digital forensic scientists, I put together the following recommendations for a good theoretical and practical background.

EWF Tools: working with Expert Witness Files in Linux

Expert Witness Format (EWF) files, often saved with an E01 extension, are very common in digital investigations. Many forensic tools support E01 files, but many non-forensic tools don’t. This is a problem if you are using other tools, like many Linux utilities to try to do an investigation.

