Using Scalpel for data carving
Scalpel was created as an improvement of a much earlier version of foremost. Scalpel aims to address the high CPU and RAM usage issues of foremost when carving data.
Specifying file types in Scalpel
Unlike foremost, file types of interest must be specified by the investigator in the Scalpel configuration file. This file is called scalpel.conf
and is located at etc/scapel/
:
To specify the file types, the investigator must remove the comments at the start of the line containing the file type as all supported file types are commented out with a hashtag at the beginning of the file type. The following screenshot shows the default Scalpel configuration file (scalpel.conf
) with all the file types commented out. Notice that each line begins with a hashtag:
We...