Research | Practice

2016-11-21

[How To] Forensic Data Recovery in Linux - tsk_recover

Monday, November 21, 2016 Posted by Unknown , , , No comments
This week we will talk about The Sleuth Kit, and specifically the tool tsk_recover. tsk_recover is a useful tool for allocated and unallocated file recovery. tsk_recover is a good quick solution, but in terms of performance, other tools tend to carve data better. I recommend using this in conjunction with other tools in an automated processing chain.


0 comments:

Post a Comment