Professional Documents
Culture Documents
Brian Carrier
Set of tools to analyze device images
http://Sleuthkit.org
http://wiki.sleuthkit.org
Disk Tools
Disk Tools
These tools can be used to detect and remove a Host Protected Area (HPA) in an ATA
disk. A HPA could be used to hide data so that it would not be copied during an
acquisition. These tools are currently Linux-only.
disk_sreset: This tool will temporarily remove a HPA if one exists. After the disk is reset,
the HPA will return.
disk_stat: This tool will show if an HPA exists.
img_stat
Image Formats
img_stat
In Action
IMAGE FILE INFORMATION
-------------------------------------------Image Type: raw
Size in bytes: 2000683008
Image Types
Volume Types
In Action
Image type
Sector size
Partition tables
This is the
Partition
Number
Slot
----00:00
00:01
-----
Start
0000000000
0000000062
0001922000
0003905504
End
0000000061
0001921999
0003905503
0003907583
Length
0000000062
0001921938
0001983504
0000002080
Description
Unallocated
Win95 FAT32 (0x0C)
NTFS (0x07)
Unallocated
In Action
sansforensics@SIFT-laptop:/cases/REDD$ mmcat red.001 2 > fat.red
In Action
sansforensics@SIFT-laptop:/cases/REDD$ mmcat red.001 3 > ntfs.red
Must
Extracted using
For
fsstat
Full path
fls - Usage
fls in Action
fls in Action
File attributes
File name
Size
ffind in Action
icat in action
icat in action
icat in action
Grabbing the MFT for analyseMFT