File recovery and data carving with Foremost
Foremost is a simple and effective CLI tool that carves and recovers files by reading the headers and footers of the files. We can start Foremost by clicking on Applications | 11 - Forensics | Foremost. However, I prefer starting Foremost from the Terminal within the folder containing our sample acquired files, which will simplify the entire process without errors. So, let’s get started:
- If you haven’t yet downloaded the sample forensic acquisition file, you can do so now by clicking on this link:
https://cfreds-archive.nist.gov/FileCarving/Images/L0_Documents.dd.bz2
- Once this file has been downloaded, I recommend creating a new folder in the
Downloads
folder by right-clicking in theDownloads
folder and clicking on Create Folder. We will call this folderForemost
. We will also create folders for each tool as we move along in this chapter to avoid having a clutteredDownloads
folder, and for the sake...