| 
  • If you are citizen of an European Union member nation, you may not use this service unless you are at least 16 years old.

  • Stop wasting time looking for files and revisions. Connect your Gmail, DriveDropbox, and Slack accounts and in less than 2 minutes, Dokkio will automatically organize all your file attachments. Learn more and claim your free account.

View
 

Sleuthkit

Page history last edited by Patrick 1 year, 8 months ago

NTFS - Video 5 (30 minutes)

Sleuthkit

 

Lecture Overview:

 

  • Install Sleuthkit and use it to forensically analyze an image of a file system:

 

    • Install SleuthKit under Mint - (0:40)
    • fsstat - (3:36, 14:42)
    • fls - (4:11, 19:00)
    • SleuthKit Overview - (5:02)
    • NTFS & SleuthKit - (7:17)
    • Conceptual Model of SleuthKit - (9:32)
    • Command line utilities - (10:41)
    • ils - (11:54, 18:05)
    • example usage - (13:42)
    • File Types - (19:59)
    • Find Inodes of Deleted Files - (20:28)
    • istat - (20:54)
    • Recover a file - (23:14)
    • icat - (23:54)
    • commands on an NTFS file system - (25:03) 

 

 

Download:

 

 

Additional Resources:

 

 

 

All Course Lectures  

 

 

Comments (0)

You don't have permission to comment on this page.