file carving tools
TRANSCRIPT
Digital forensics with Kali Linux
Marco Alamanni
Video 4.2
File carving tools
In this Video, we are going to take a look at…
• How to recover deleted files with The Sleuth Kit.
• How to recover deleted files using carving tools:Foremost , Scalpel and Photorec.
File carving tools
● Three CLI carving tools included by default on Kali Linux:Foremost , Scalpel and Photorec.
● These tools extract files from raw disk sectors.
● Use a database of headers and footers for several file formats.
● Also work on disk images.
● Sample image from the Digital Forensics Tool Testing Images page:http://dftt.sourceforge.net/
Foremost
● Foremost has been developed by Jesse Kornblum and Kris Kendall at the Air Force Office of Special Investigations and later updated by Nick Mikus of the Naval Postgraduate School.
● Default configuration file is /etc/foremost.conf.
● We edit it only to enable the recovery of formats not included in the default configuration.
Scalpel
● Scalpel is a rewrite of Foremost and the latest version available on Kali Linux is the 1.60.
● The latest version is the 2.0 and the source is available at The Sleuth Kit github repository: https://github.com/sleuthkit/scalpel
● The configuration file is /etc/scalpel/scalpel.conf
● Unlike Foremost, we have to edit the configuration file uncommenting all the file formats we want to recover.
Photorec
● PhotoRec has been developed by Christophe Grenier, the developer of TestDisk.
● Can recover many different file formats and has a text-based user interface like TestDisk.
● Photorec web page provides valuable information on how the program works and how to use it:http://www.cgsecurity.org/wiki/PhotoRec
Next Video
Extracting data with Bulk Extractor