| 
  • If you are citizen of an European Union member nation, you may not use this service unless you are at least 16 years old.

  • Buried in cloud files? We can help with Spring cleaning!

    Whether you use Dropbox, Drive, G-Suite, OneDrive, Gmail, Slack, Notion, or all of the above, Dokkio will organize your files for you. Try Dokkio (from the makers of PBworks) for free today.

  • Dokkio (from the makers of PBworks) was #2 on Product Hunt! Check out what people are saying by clicking here.

View
 

Sleuthkit

Page history last edited by Patrick 3 years, 3 months ago

NTFS - Video 5 (30 minutes)

Sleuthkit

 

Lecture Overview:

 

  • Install Sleuthkit and use it to forensically analyze an image of a file system:

 

    • Install SleuthKit under Mint - (0:40)
    • fsstat - (3:36, 14:42)
    • fls - (4:11, 19:00)
    • SleuthKit Overview - (5:02)
    • NTFS & SleuthKit - (7:17)
    • Conceptual Model of SleuthKit - (9:32)
    • Command line utilities - (10:41)
    • ils - (11:54, 18:05)
    • example usage - (13:42)
    • File Types - (19:59)
    • Find Inodes of Deleted Files - (20:28)
    • istat - (20:54)
    • Recover a file - (23:14)
    • icat - (23:54)
    • commands on an NTFS file system - (25:03) 

 

 

Download:

 

 

Additional Resources:

 

 

 

All Course Lectures  

 

 

Comments (0)

You don't have permission to comment on this page.