Forensic Data Recovery in Windows - Photorec

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024

Комментарии • 38

  • @martinlastname8548
    @martinlastname8548 4 года назад +6

    Many thanks! Seems like I am getting my degree from you

  • @_productivity__nill_1131
    @_productivity__nill_1131 6 лет назад +2

    Only channel with good tutorials

  • @Juliapak
    @Juliapak 5 лет назад +1

    Thank you for making these videos. Wondering if you know anything about getting forensic data off a cell phone? I'm a programmer (app maker here) but recently have come across a phone which cannot be unlocked (has screen pattern) because well...person is dead. Family wants the data from the phone but for various reasons cannot get into it. I know how to reset a screen pattern, however that process is destructive to data (basically it resets the phone entirely). Im doing this mainly because I'm very curious. And yes I'm aware of Riff box etc etc.

  • @Love-ms5gs
    @Love-ms5gs 4 года назад +1

    I need some data from my downed laptop where i needed to restore windows on. I used photorec on linux before. How can i just start photorec on windows ?

  • @ArmanMalik-wu7vy
    @ArmanMalik-wu7vy 2 года назад

    Awesome video

  • @sharifi101
    @sharifi101 5 лет назад

    Hi, I used a software that was based on DBAN(Darik’s Boot and Nuke) to overwrite data in Hdd and i used only one passed functionality of the software which it filled zero in entire sectors of hdd.. I tried to recover this overwritten data back with 10 famous tools but couldn’t able to recover the data back.. if you know any technique or tools for recovering overwritten data it will be awesome to suggest me... I am new in digital forensics area.. Thanks for making such as good videos, I learned a lot from u...👌👌

  • @didyouknowamazingfacts2790
    @didyouknowamazingfacts2790 Год назад

    I'm just wondering can this be used on a BitLocker drive? I have an old drive from an old laptop. I would like to recover some file. But didn't realize it was bitlocked.

  • @pragyaparamitadas4613
    @pragyaparamitadas4613 3 года назад

    Thanks for this vedio.. it is very helpful... I have a question after data acquisition using ftk u told that we need to combine this multipart raw disk images into full raw disk images... how to do that... its for my college project... I need to complete it immediately... please rply me asap

  • @andersondavid83
    @andersondavid83 4 года назад +1

    Hi brother plz help ! My SD card in camcorder got corrupted! I lost my video files I need to recover as it contains wedding videos of my first assignment plz I need ur guidence! Is it possible to recover with this method from ur video

  • @caiofdacosta
    @caiofdacosta 4 года назад

    Would you say PhotoRec will recognize a photo if it's inside a zip file? Do you think it would pop up if I searched for png only?

  • @izucykaaa
    @izucykaaa 4 года назад +1

    My pictures are infected with one cryptovirus. Appear in format .leto. Can I use Photorec for recovery? Is it ok Photorec in my situation?

    • @jacqrmr
      @jacqrmr 4 года назад

      That's exactly what I'm trying. But it seems that it depends on how many times the files has been overwriten... Something like that. And if we are lucky enough and this cryptovirus - that is a variant of STOP Djvu - doesn't corrupt our files when it was deleted... :'(

    • @DFIRScience
      @DFIRScience  4 года назад +1

      If you have ransomware, try to submit some samples to www.nomoreransom.org/ They may have keys for whatever got you. DO NOT PAY. Nomoreransom is a free service from security orgs.
      Photorec for recovery - it depends on a lot of factors. If the file was encrypted, and the original data was simply deleted, AND the hard drive is HDD - recovery is likely. If you are using a solid state drive, the file was encrypted in-place, or securely deleted, then the chance of recovery is much less.
      There are many things to consider. Try www.nomoreransom.org/ first. If that fails, then try file carving.

  • @jesseq.4489
    @jesseq.4489 6 лет назад

    Hi there, I have a Micro SD card which simply could not be read (regardless PC/MAC/Mobile Device). It prompts me to format before I can use it... so I don't really have a 'disk image' to use Photorec on in order to recover the image files I still have on it. Thoughts?

  • @Seth_Samson
    @Seth_Samson 6 лет назад +1

    can we bring back filenames ... from those F00152424.jpg to original name ??? somehow

  • @jorgemiranda1560
    @jorgemiranda1560 2 года назад

    Hi, I have a question; How to add your own file extensions when recovering uncommon files like .con, .dat, .desc, .ai, .raw, .dds, etc. Can you make a video about this please....

    • @DFIRScience
      @DFIRScience  2 года назад

      File recovery is often based on a file-type header. Basically the data structure of the file. RAW and DD, for example, may not have a specific structure. If your file has a structure, you could use something like scalpel (linux.die.net/man/1/scalpel) with custom headers to try to carve it. If the file type does not have a standard structure, you will probably have to carve it manually.
      Alternatively, you might be able to use file system information with something like The Sleuth Kit to identify where the data is saved and "carve" that way.
      I will think about making a video about carving with scalpel. Thanks for your question!
      File types supported by Photorec (www.cgsecurity.org/wiki/File_Formats_Recovered_By_PhotoRec)

  • @iloveyou143639
    @iloveyou143639 6 лет назад

    Hii, Thanks for the video, this is really good one, but could you please explain us the following questions, is photorec is used to recover the deleted images ? because in your demonstration we see only the recovered jpeg images from the Forensic disk image which is in DD format. when you imaging the USB in previous videos i see images are there, so am still confused the photorec is used for recovering the lost image ?

    • @DFIRScience
      @DFIRScience  6 лет назад

      Sorry that wasn't clear. Yes, photorec can recover deleted data (not just images). It can even recover partial files if some of the data is missing. It is great for deleted data recovery.

    • @iloveyou143639
      @iloveyou143639 6 лет назад

      DFIR.Science thanks, really appreciate it.

  • @Telebellyy
    @Telebellyy 3 года назад

    Hi, I was hoping to use this for my Mac but the 64bit seems quite complicated to install. Can I just install the 32bit version or are there any easier instructions to install the 64bit version? thanks

    • @DFIRScience
      @DFIRScience  3 года назад

      Do you mean installing with brew on macOS? www.cgsecurity.org/wiki/TestDisk_Download

  • @ahmedwolf1472
    @ahmedwolf1472 5 лет назад

    would you help ransomeware victims ? and the photorec recovers like 2% of deleted files by the viruse ... i mean if it can recover some why cant recover all thank you very much .

  • @mujehoxe4811
    @mujehoxe4811 2 года назад

    how did combine the images into one .dd image?

    • @DFIRScience
      @DFIRScience  2 года назад +1

      In Linux you can use 'cat'
      so if I have some images in a directory:
      image.000
      image.001
      image.002
      Then I can run:
      cat image.* > bigimage.dd
      Note if you have one large raw file, you can use the "split" command to break it into parts.

  • @benlange7124
    @benlange7124 3 года назад

    Does it work to recover files from an android phone after a factory reset?

  • @efendiev2035
    @efendiev2035 3 года назад

    My pc was attacked agho virus befor two days i don't know what i do 😔 i trying decrypter but not working because i need online key not offline key pls help mi what can do :( i have so important files :(

    • @DFIRScience
      @DFIRScience  3 года назад +1

      www.nomoreransom.org/

    • @efendiev2035
      @efendiev2035 3 года назад

      @@DFIRScience it is work if my attacks was witch online key needed

  • @george4a
    @george4a 4 года назад

    hi how can recover deleted data?not image

    • @DFIRScience
      @DFIRScience  3 года назад

      Hello - Photorec has the ability to recover many types of files, not just images. What type of data are you trying to recover?

    • @arjunadhi9117
      @arjunadhi9117 3 года назад

      @@DFIRScience mp4 ?

  • @Apno_Itihas
    @Apno_Itihas 2 года назад

    Don't show path in user variables

    • @DFIRScience
      @DFIRScience  2 года назад

      If it is not there for the user, you can create it.

  • @stepbytech6098
    @stepbytech6098 2 года назад

    hello sir please help me I'm in very depression😭😭🙏😭😭