Professional Documents
Culture Documents
Source : https://hacklido.com/blog/383-introduction-to-forensic-data-carving
MORE ABOUT DATA CARVING
THE DATASET IS A MEMORY IMAGE OF A FAT32 FILE SYSTEM THAT INCLUDES MULTIPLE DELETED FILES OF DIFFERENT FILE FORMATS
AND EXTENSIONS. THE DESCRIPTION OF EACH FILE, INCLUDING ITS HASH IS GIVEN AT THE BOTTOM OF THE DOWNLOAD PAGE.
AFTER DOWNLOADING THE ZIP OF THE DATA SET, EXTRACT IT TO A FRESH DIRECTORY AND PROCEED FURTHER.
Source : https://hacklido.com/blog/383-introduction-to-forensic-data-carving
FILE RECOVERY WITH FOREMOST
Foremost is a widely popular command line tool in the world of digital forensics that
recovers files from unallocated space using file headers and footers. The tool is
powerful yet easy to use due to its simple syntax.
A simple command to carve everything The output directory that we specified during
from the image file looks like this: carving contains all the files that are successfully
carved by foremost, organized into different sub-
directories by file type. Furthermore, an audit.txt
file is generated that contains all the details and
findings listed in a neat format.
Source : https://hacklido.com/blog/383-introduction-to-forensic-data-carving
HERE’S A SAMPLE OF JPG FILES THAT ARE
SUCCESSFULLY RECOVERED BY FOREMOST:
A BETTER WAY TO USE THE TOOL IS TO SPECIFY SELECTED FILE EXTENSIONS TO CARVE TO REDUCE THE TIME TAKEN TO RECOVER
FILES. WHILE IT IS A WISE CHOICE TO SPECIFY FILE TYPE DURING CARVING, THE EXTENSION MUST BE KNOWN TO USE THIS METHOD.
THE SYNTAX TO CARVE SELECTED FILE TYPES LOOKS LIKE THIS:
FOREMOST -I <INPUT_FILE> -T <EXTENSIONS> -O <OUTPUT_DIRECTORY>
Source : https://hacklido.com/blog/383-introduction-to-forensic-data-carving
WE WILL TALK ABOUT ONE MORE TOOL
FILE RECOVERY WITH SCALPEL
FILE RECOVERY WITH SCALPEL
Source : https://hacklido.com/blog/383-introduction-to-forensic-data-carving
This file is called scalpel.conf and is located at etc/scalpel/
Source : https://hacklido.com/blog/383-introduction-to-forensic-data-carving
AFTER SPECIFYING THE FILE FORMATS TO CARVE, USE SCALPEL WITH THE FOLLOWING SYNTAX:
SIMILAR TO FOREMOST, ALL RECOVERED FILES ARE ORGANIZED INTO DIFFERENT SUB-
DIRECTORIES BASED ON THE FILE FORMAT.
PLEASE NOTE THAT NEITHER FOREMOST, NOR SCALPEL RETURNS FILES WITH THEIR ORIGINAL NAMES, AND THE RESULT OFTEN
CONTAINS DUPLICATES. THUS, REMEMBER TO USE BOTH TOOLS TO VERIFY YOUR RESULTS, AND DO NOT RELY ON A SINGLE TOOL.
Source : https://hacklido.com/blog/383-introduction-to-forensic-data-carving
THANK YOU