dfir.blog
  • Unfurl
  • Hindsight
  • Visualizations
  • Open Source
  • Presentations & Interviews
Ryan Benson

Ryan Benson

Deleted File Recovery using foremost
Digital Forensics

Deleted File Recovery using foremost

In this post, we'll use the Linux program foremost to recover files, both existing and deleted, from a .dd image. foremost is what is as known as a data-carving utility. It operates by examining data, bit by bit, and extracting sets of data that meet a defined pattern.
Aug 6, 2011 5 min read
Slack Space
Digital Forensics

Slack Space

Slack space can exist when a file's size is not a multiple of the file system's cluster size. As a little refresher, a sector is the smallest amount of data that a hard drive can read or write at one; in many cases, this is 512
Jul 26, 2011 2 min read
Digital Forensics

Imaging Using dcfldd

In this post, a 128MB USB thumb drive will be imaged on a Linux system using dcfldd onto a 1GB USB thumb drive. dcfldd is an improved version of dd; most of the syntax is identical, just a few functions have been added. As a quick aside, this post is
Jul 2, 2011 4 min read
← Newer Posts Page 4 of 4
dfir.blog © 2026
Powered by Ghost