Beginner Introduction to The Sleuth Kit (command line)

Поделиться
HTML-код
  • Опубликовано: 21 ноя 2024

Комментарии • 48

  • @deever563
    @deever563 7 лет назад +5

    This is a great tutorial. It really helps confirm that I'm accurately reading hex tables from FTK Imager.

  • @thebestisyettocome7
    @thebestisyettocome7 11 месяцев назад

    Great tutorial, you explained how to use Sleuth Kit very clearly.

  • @Bear42o1
    @Bear42o1 Год назад

    Awesome. Taking a forensics course atm, and this was a huge help.

  • @maiwand4023
    @maiwand4023 4 года назад +2

    Thanks a lot. Would be happy about some more parts with more detailed forensic analytics

  • @wvdhoute
    @wvdhoute 2 года назад

    Great way to explain, calm and clear. Thanks

  • @rahulkatiyar9283
    @rahulkatiyar9283 3 года назад

    Nice video. Gives understanding about the basic things that you could do using TSK

  • @ElDj1794
    @ElDj1794 2 года назад +1

    This video helped me out a lot, thank you.

  • @pimc172
    @pimc172 4 года назад

    didnt expected to be taught what options are and how to use the help on such an advanced tool but still, I learned some stuff

  • @Memerzaryab
    @Memerzaryab Год назад

    from where i can dowload images ..i want to download the c drive image.. i want to look into ntfs data

  • @tanushreepai7545
    @tanushreepai7545 3 года назад

    Sir could you please tell me which tool should I use on a windows system to create the raw .dd image of my usb. I guess guyimager can be used only on linux. Thank you for this great video!!

  • @tangducbao7309
    @tangducbao7309 5 лет назад +1

    Thanks alot, guy

  • @siewkim9658
    @siewkim9658 4 года назад +1

    such an awesome voice!!

  • @OxygenOS
    @OxygenOS 3 года назад

    New sub! This works for me but i mostly work on windows...

  • @lowlatent-c9294
    @lowlatent-c9294 4 года назад +1

    Great content...glad I found your channel. New sub.

  • @abhiramabhi5885
    @abhiramabhi5885 8 месяцев назад

    where can i get the dd file ?

  • @leonewton253
    @leonewton253 Год назад

    you failed to mention the command to acquire the image

  • @jonathafernandes5179
    @jonathafernandes5179 6 лет назад

    Thank you very much, excellent content

  • @joshmileikowsky
    @joshmileikowsky 6 лет назад

    how would you check for deleted files. I saw that you spoke about it briefly. Perhaps I missed it?

    • @000verfloww
      @000verfloww 5 лет назад +1

      In TSK 4 you could use Tsk_recover to recover files and deleted ones that will be in the unallocated spaces

  • @nidacanpolat3316
    @nidacanpolat3316 2 года назад

    It is easy to dd image of USB, but how to dd image of CD or DVD?

    • @DFIRScience
      @DFIRScience  2 года назад +1

      You won't be able to dd a physical image of a CD/DVD, but you can technically DD a logical image. Instead, it is better to use ISO creation software built into most systems these days.

  • @ryanvanderberg
    @ryanvanderberg 5 лет назад

    how did you get that .info file when from the .dd image?

    • @DFIRScience
      @DFIRScience  5 лет назад +1

      That is an imaging log file from Guymager. The image was not created with dd, although it is a raw disk image. .dd is a common raw extension. You may also see .raw or .000

  • @behzadsatari
    @behzadsatari 6 лет назад

    Thanks It was helpful

  • @zn475
    @zn475 7 лет назад

    thanks for this great tutorial.i write mmls Image1.dd ,which Image1.dd is my usb, but i take the message . This gives me the information ,my usb image its a logical disk image?
    thanks

    • @DFIRScience
      @DFIRScience  7 лет назад

      Hello. image1.dd may be a logical disk image. Try fls image1.dd. If you see a directory list, then it is a logical disk image.

  • @danielverdin7185
    @danielverdin7185 7 лет назад

    Thanks!

  • @EmadSaeed
    @EmadSaeed 7 лет назад

    How to identify contents of a large file of about 90GB. the file with no extension and I really want to know what's inside id. I found it inside my c: partition called "Free space" with another sibling file called "Idle space"

    • @DFIRScience
      @DFIRScience  7 лет назад +1

      You can use the 'file' utility to try to find some information about the file signature. I made a video for you at ruclips.net/video/-vsfm1IqmWA/видео.html
      Other than that, you could open the huge file in a hex editor and look at the signature manually.

  • @marcus.edmondson
    @marcus.edmondson 7 лет назад

    Nice tutorial!

    • @DFIRScience
      @DFIRScience  7 лет назад +1

      Thanks a lot. Let me know if you would like something specific.

  • @parinurmamat8526
    @parinurmamat8526 2 года назад

    How to Download it for mac? (Sleuth Kit)

    • @DFIRScience
      @DFIRScience  2 года назад

      You will have to compile the Sleuthkit on Mac. Download the 'source code' from here: sleuthkit.org/sleuthkit/download.php

  • @rohitshrivastava58
    @rohitshrivastava58 6 лет назад

    Great... thanks a lot!

  • @bhaskarmallarapu2392
    @bhaskarmallarapu2392 7 лет назад

    nice explantion

  • @kirbfx
    @kirbfx 5 лет назад +5

    Take a shot every time he says “mmkay” 😄 🥃

    • @DFIRScience
      @DFIRScience  5 лет назад +4

      while 1; print mmkay; done

    • @kirbfx
      @kirbfx 3 года назад

      @Adrian Chad Spam harder, will yah?? 😒

  • @bikdigdaddy
    @bikdigdaddy 11 месяцев назад

    this was of great help. thank you very much.

  • @lilygarcia148
    @lilygarcia148 5 лет назад +1

    sorry, can you show me how to create an image first?

  • @kammychakotra
    @kammychakotra 7 лет назад

    fcat command is not working....Can u please tell me ??

  • @friedkitchenrce
    @friedkitchenrce 3 года назад

    anyone here from picoCTF?

  • @timburke4132
    @timburke4132 2 года назад

    Ok, obviously I am strong like bull, smart like tractor. how the hell does a person learn what the meaning of MGB/5 or whatever it is you said? Apparently, the cyber security class I am taking labeled "Basic" is NOT basic, as I don't have a clue what you said, and Sleuthkit is still an absolute mystery. Where do I start if this was "mandarin" to me?

    • @DFIRScience
      @DFIRScience  2 года назад

      A great place to start is with this free book on forensics using Linux. It covers many basic computing concepts and commands before getting into the forensics. It's all hands-on.
      linuxleo.com/Docs/LinuxLeo-4.95.1.pdf
      linuxleo.com/
      The Sleuth Kit is all about parsing file systems. You can either learn how file systems work and then learn TSK or learn TSK to explore how file systems work. Whatever approach works best for you. The book linked above walks through practical examples while explaining.

    • @DFIRScience
      @DFIRScience  2 года назад

      And any vocab you don't understand, or any questions in general, feel free to post them and I will try to answer. You can also DM me on Twitter @DFIRScience