Disk Forensics
Disk Forensics includes where you are required to investigate the files which were deleted off the system.
Mounted Devices
The devices that were mounted to the devices can be identified with the commands
Quick Wins
Every device blocks connected to the UNIX systems store its contents in binary format and everything connected is CATable / GREPable
Once the mounted device is identified we can cat / grep the device block
Forensic Way
With the
dcfldd
With this file transferred to the attacker machine we can run utilities like
testdisk
orphotorec
to investigate this dd file
Last updated
Was this helpful?