官术网_书友最值得收藏!

NTFS Analysis with The Sleuth Kit

The Sleuth Kit is a collection of command-line tools (and also a library) for the forensic analysis of drive images. These tools can help you with analysis of both volume and file system data (in a non-intrusive fashion, of course). It's cross-platform, so you can use any operating system you like to work with this toolkit. It supports both RAW and E01 images, so you can use any image that you acquired while following the previous recipes. This collection of tools will be very useful in your future digital forensic examinations: it supports a wide range of file systems, including NTFS, FAT, ExFAT, EXT2, EXT3, EXT4, HFS, and so on.

主站蜘蛛池模板: 平昌县| 衡阳市| 沙坪坝区| 那曲县| 长治县| 仲巴县| 合阳县| 略阳县| 米易县| 日喀则市| 汾西县| 全南县| 天台县| 新疆| 望奎县| 江陵县| 黑龙江省| 呼玛县| 五家渠市| 田林县| 虎林市| 旬邑县| 涡阳县| 台北市| 内江市| 本溪| 滨州市| 同仁县| 瓮安县| 泾阳县| 张家口市| 西华县| 西和县| 睢宁县| 错那县| 大荔县| 吉木萨尔县| 莱州市| 双江| 武川县| 丰宁|