File Recovery and Data Carving Tools
Now that we’ve learned how to create forensic images of evidence, let’s look at the file recovery and data carving process, using specific tools in Kali Linux.
File carving retrieves data and files from unallocated space using specific characteristics such as the file structure and file headers, instead of traditional metadata created by, or associated with, filesystems. A simple way to think of file carving is to think of an ice sculpture. It starts off with a huge block of ice, which, when given to a skilled individual, can be chipped away into a piece of art. In the same way, DFIR investigators and analysts can create a forensic image using any of the tools mentioned in the previous chapter, and then use a variety of tools to extract useful data and files from the acquired forensic image.
In this chapter, we’ll cover the following topics:
- File basics
- Downloading sample files for the labs in this chapter ...