DFS101: 7.4 Data Recovery - The Sleuth Kit

Поделиться
HTML-код
  • Опубликовано: 25 окт 2024

Комментарии • 14

  • @andreasjanzen8823
    @andreasjanzen8823 2 года назад

    Excellent introduction, exactly what I needed to get started with the Sleuth Kit. Starting from zero, well structured, easy to understand. Thank you!!

  • @negative-example
    @negative-example Год назад

    For me, IT security and forensics looks like one of top-skill areas of IT. Funny to see educating forensics video which explains, what is "ls" and "cat".

  • @marvelousekpenyong4343
    @marvelousekpenyong4343 5 месяцев назад +1

    Thank you for this course sir. I have a question please. All these disk images that were analysed using photorec, tsk_recover and sleuthkit. You didn't say how they were captured. Were they captured using the FTK imager or another software. Thank you. Hoping for your response.

  • @calebkulujili1395
    @calebkulujili1395 4 месяца назад

    How can you approach a scenario where yo have a linux OS in HDD/SDD then formatted with windows, but you need the files that were in the linux system

  • @andry8536
    @andry8536 Год назад

    Hello, very good video, helping a lot, starting from zero with Sletuth kit and Digital Forensics. I have a question, when determining the partition, in this case FAT32, is it a good practice to extrapolate that specific partition into a separate file? in such a way that is not necessary to specify each time the offset to move? Thank you

  • @ДмитрийКузнецов-я4д

    I am absolutely zero in this sphere yet. i am not completely understand and comprehend this topics. Can you tell me what am i gonna start with? maybe python or what? Thanks for advanced

  • @saumyatyagi4214
    @saumyatyagi4214 3 года назад +1

    what if the Disk is encrypted? Is there any s/w to decrypt the data

    • @adrpgt
      @adrpgt 3 года назад

      in fls command, there is the -k parameter : "-k password: Decryption password for encrypted volumes"

  • @dulajperera63
    @dulajperera63 8 месяцев назад

    How to create a .dd image file

  • @mohammedbilal6226
    @mohammedbilal6226 3 года назад

    Just to clarify, a 001 File is the same as a .dd file?

    • @DFIRScience
      @DFIRScience  3 года назад +2

      Usually, yes. Both are very often "RAW" disk images - no additional structure or compression, just like you would find on the original disk. That is likely, but you should always confirm before working with the image.

  • @SabrinaXe
    @SabrinaXe 6 месяцев назад

    12:54 deleted