| 
  • If you are citizen of an European Union member nation, you may not use this service unless you are at least 16 years old.

  • Work with all your cloud files (Drive, Dropbox, and Slack and Gmail attachments) and documents (Google Docs, Sheets, and Notion) in one place. Try Dokkio (from the makers of PBworks) for free. Now available on the web, Mac, Windows, and as a Chrome extension!

View
 

Sleuthkit

Page history last edited by Patrick 2 years, 8 months ago

NTFS - Video 5 (30 minutes)

Sleuthkit

 

Lecture Overview:

 

  • Install Sleuthkit and use it to forensically analyze an image of a file system:

 

    • Install SleuthKit under Mint - (0:40)
    • fsstat - (3:36, 14:42)
    • fls - (4:11, 19:00)
    • SleuthKit Overview - (5:02)
    • NTFS & SleuthKit - (7:17)
    • Conceptual Model of SleuthKit - (9:32)
    • Command line utilities - (10:41)
    • ils - (11:54, 18:05)
    • example usage - (13:42)
    • File Types - (19:59)
    • Find Inodes of Deleted Files - (20:28)
    • istat - (20:54)
    • Recover a file - (23:14)
    • icat - (23:54)
    • commands on an NTFS file system - (25:03) 

 

 

Download:

 

 

Additional Resources:

 

 

 

All Course Lectures  

 

 

    You now

Comments (0)

You don't have permission to comment on this page.