Although stated in a previous writeup concerning computer forensics, it can be quite an expensive endeavor. Some of the things that you may come across whereby an expense is needed you may be able to get away with utilizing, Linux. When we discussed the need for write-blockers, it was said that you needed to purchase an expensive write-blocker that would allow you to make a disk image with ease of mind. However, you don't really need to do this. This article will explain how you can utilize Linux in order to pull a disk image and then feed it into ProDiscover and of course, bypass the need for a write blocker. This document will also detail how you can recover files that were deleted for a forensic investigation.

