Test Results for Forensic Media Preparation Tool: dc3dd: Version 7.0.0

NCJ Number
Date Published
December 2011
27 pages
This report presents the results from testing the wipe function of dc3dd version 7.0.0 against the "Forensic Media Preparation Tool Text Assertions and Test Plan Version 1.0."
The dc3dd tool can be used for a variety of forensic tasks (e.g., disk imaging or wiping media for reuse). The testing reported only examined the use of the tool to overwrite media for reuse. In all the test cases run against dec3dd version 7.0.0, all visible sectors were successfully overwritten. Sectors hidden by an HPA were also overwritten; however, sectors hidden by a DCO were not removed. By design, the tool does not remove either Host Protected Areas (HPAs) or DCOs; however, the Linux test environment used automatically removed the HPA on test drives, allowing sectors hidden by an HPA to be overwritten by the tool. The remaining sections of the report describe how the tests were conducted and provide documentation of test case details that support the report summary. One section of the report gives the selection of each test case from the set of possible cases defined in the test plan for forensic media preparation tools. The test cases are generally selected based on features offered by the tool. Another section lists hardware and software used to run the test cases, with links to additional information about the items used. This is followed by a section that contains a description of each test case, listing all test assertions that apply, their expected results, and the actual results. Extensive tables

