Digital forensics with Kali Linux
Marco Alamanni
Video 4.2
File carving tools
In this Video, we are going to take a look at…
• How to recover deleted files with The Sleuth Kit.
• How to recover deleted files using carving tools:
Foremost, Scalpel and Photorec.
File carving tools
●
Three CLI carving tools included by default on Kali Linux:
Foremost, Scalpel and Photorec.
●
These tools extract files from raw disk sectors.
●
Use a database of headers and footers for several file formats.
●
Also work on disk images.
●
Sample image from the Digital Forensics Tool Testing Images page:
http://dftt.sourceforge.net/
Foremost
●
Foremost has been developed by Jesse Kornblum and Kris Kendall at the Air
Force Office of Special Investigations and later updated by Nick Mikus of the
Naval Postgraduate School.
●
Default configuration file is /etc/foremost.conf.
●
We edit it only to enable the recovery of formats not included in the default
configuration.
Scalpel
●
Scalpel is a rewrite of Foremost and the latest version available on Kali Linux is
the 1.60.
●
The latest version is the 2.0 and the source is available at The Sleuth Kit github
repository: https://github.com/sleuthkit/scalpel
●
The configuration file is /etc/scalpel/scalpel.conf
●
Unlike Foremost, we have to edit the configuration file uncommenting all the file
formats we want to recover.
Photorec
●
PhotoRec has been developed by Christophe Grenier, the developer of TestDisk.
●
Can recover many different file formats and has a text-based user interface like
TestDisk.
●
Photorec web page provides valuable information on how the program works
and how to use it:
http://www.cgsecurity.org/wiki/PhotoRec
Next Video
Extracting data with Bulk Extractor

File carving tools

  • 1.
    Digital forensics withKali Linux Marco Alamanni Video 4.2 File carving tools
  • 2.
    In this Video,we are going to take a look at… • How to recover deleted files with The Sleuth Kit. • How to recover deleted files using carving tools: Foremost, Scalpel and Photorec.
  • 3.
    File carving tools ● ThreeCLI carving tools included by default on Kali Linux: Foremost, Scalpel and Photorec. ● These tools extract files from raw disk sectors. ● Use a database of headers and footers for several file formats. ● Also work on disk images. ● Sample image from the Digital Forensics Tool Testing Images page: http://dftt.sourceforge.net/
  • 4.
    Foremost ● Foremost has beendeveloped by Jesse Kornblum and Kris Kendall at the Air Force Office of Special Investigations and later updated by Nick Mikus of the Naval Postgraduate School. ● Default configuration file is /etc/foremost.conf. ● We edit it only to enable the recovery of formats not included in the default configuration.
  • 5.
    Scalpel ● Scalpel is arewrite of Foremost and the latest version available on Kali Linux is the 1.60. ● The latest version is the 2.0 and the source is available at The Sleuth Kit github repository: https://github.com/sleuthkit/scalpel ● The configuration file is /etc/scalpel/scalpel.conf ● Unlike Foremost, we have to edit the configuration file uncommenting all the file formats we want to recover.
  • 6.
    Photorec ● PhotoRec has beendeveloped by Christophe Grenier, the developer of TestDisk. ● Can recover many different file formats and has a text-based user interface like TestDisk. ● Photorec web page provides valuable information on how the program works and how to use it: http://www.cgsecurity.org/wiki/PhotoRec
  • 7.
    Next Video Extracting datawith Bulk Extractor