file carving tools

7

Click here to load reader

Upload: marco-alamanni

Post on 22-Jan-2018

94 views

Category:

Software


0 download

TRANSCRIPT

Page 1: File carving tools

Digital forensics with Kali Linux

Marco Alamanni

Video 4.2

File carving tools

Page 2: File carving tools

In this Video, we are going to take a look at…

• How to recover deleted files with The Sleuth Kit.

• How to recover deleted files using carving tools:Foremost , Scalpel and Photorec.

Page 3: File carving tools

File carving tools

● Three CLI carving tools included by default on Kali Linux:Foremost , Scalpel and Photorec.

● These tools extract files from raw disk sectors.

● Use a database of headers and footers for several file formats.

● Also work on disk images.

● Sample image from the Digital Forensics Tool Testing Images page:http://dftt.sourceforge.net/

Page 4: File carving tools

Foremost

● Foremost has been developed by Jesse Kornblum and Kris Kendall at the Air Force Office of Special Investigations and later updated by Nick Mikus of the Naval Postgraduate School.

● Default configuration file is /etc/foremost.conf.

● We edit it only to enable the recovery of formats not included in the default configuration.

Page 5: File carving tools

Scalpel

● Scalpel is a rewrite of Foremost and the latest version available on Kali Linux is the 1.60.

● The latest version is the 2.0 and the source is available at The Sleuth Kit github repository: https://github.com/sleuthkit/scalpel

● The configuration file is /etc/scalpel/scalpel.conf

● Unlike Foremost, we have to edit the configuration file uncommenting all the file formats we want to recover.

Page 6: File carving tools

Photorec

● PhotoRec has been developed by Christophe Grenier, the developer of TestDisk.

● Can recover many different file formats and has a text-based user interface like TestDisk.

● Photorec web page provides valuable information on how the program works and how to use it:http://www.cgsecurity.org/wiki/PhotoRec

Page 7: File carving tools

Next Video

Extracting data with Bulk Extractor