Disk Forensics
Mounted Devices
df -h
mountQuick Wins
cat /dev/sdb
sudo xxd /dev/sdb | grep -Ev '(0000 0000 0000 0000 0000 * | ffff ffff ffff ffff ffff *)'Forensic Way
dcfldd if=/dev/sdb of=/tmp/file.dd
root@raspberrypi:/home/pi# dcfldd if=/dev/sdb of=/tmp/test
256 blocks (8Mb) written.
320+0 records in
320+0 records out
root@raspberrypi:/home/pi# ls -lash /tmp/test
10M -rw-r--r-- 1 root root 10M Mar 13 10:34 /tmp/testLast updated