I was perusing the 2nd edition of Harlan Carvey's Windows Forensic
Analysis book just last night, and recall a mention of something that
might fit the bill rather early - perhaps even in the Introduction. I
recall it being remote and read only imaging.
A little googling led to this possibly helpful article:
ProDiscover out of those results looked familiar for some
reason--perhaps from Carvey's book. Their incident response product
appears to do what you want, but it leverages a remote agent and can't
work simply over the SMB share. I doubt you can get to the level you
seem to be looking for over a standard SMB share anyway, so that it
relies upon an agent shouldn't be seen as a detriment:
Want to reply to this thread or ask your own question?
You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.