SlideShare a Scribd company logo
5
Most read
7
Most read
9
Most read
Digital forensics with Kali Linux
Marco Alamanni
Section 4
File carving and data recovery
www.packtpub.com
In this Section, we are going to take a look at…
●
Introduction to file carving: unallocated and slack disk space, deleted files,
Recycle Bin.
●
File carving tools: Foremost, Scalpel and Photorec.
●
Data extraction using Bulk-extractor
Course Name
Author Name
Video 4.1
File carving overview
In this Video, we are going to take a look at…
●
Introduction to file slack and unallocated space, deleted files and the file carving
process.
• The Windows Recycle Bin and how to examine it with Rifiuti2.
Introduction to slack space
●
Smallest addressable data units on filesystems are called blocks or clusters, that
are usually 4 KB of size.
• Files generally use various blocks, the last block being only partial ly used.
• The space left between the end of the file’s data and the end of the block is
called slack space.
• Slack space can contain hidden data or remnants from previously deleted file.
Introduction to slack space
Deleted files and unallocated space
●
When a file is deleted, the relative directory entry is removed
but the entry in the file’s table remains.
• The file’s allocated blocks become unallocated; they are marked as free but not
modified until reallocated to other files.
• The unallocated blocks’ contents could be recovered using The Sleuth Kit tools
or data carving tools
Introduction to data carving
●
Data carving is the process of identifying and extracting meaningful data out of
the unallocated and slack space.
• It relies on locating the magic number of a file and copying all the data until the
end of file (EOF) marker is not found.
• It is straightforward if the file’s data blocks are contiguous, could be challenging
if the file is fragmented.
• Algorithm for file carving that also handle fragmentation has been developed
for data carving tools.
The Windows Recycle Bin
●
On modern operating systems, deleted files are usually first moved to the
Recycle Bin (on Windows) or analogous directory.
• These files are permanently deleted if the Recycle Bin is emptied or can be
restored in the original location.
• On Windows XP and earlier deleted files are placed under C:Recycler
subfolders, one for each user, and the relative information are stored in INFO2
index files.
• On Windows Vista and newer deleted files are stored under C:$Recycle.Bin
subfolders in files that begin with $I and $R.
Next Video
File carving tools

More Related Content

ODP
File carving tools
PPT
File Carving
PPTX
Advances in File Carving
PPT
File structures
PPT
PPT
File organization
PPTX
Chapter 3
PPT
Linux Forensics
File carving tools
File Carving
Advances in File Carving
File structures
File organization
Chapter 3
Linux Forensics

What's hot (19)

PPTX
file system in operating system
PPTX
Free Space Management, Efficiency & Performance, Recovery and NFS
PPT
11. Storage and File Structure in DBMS
PPTX
File management
PPTX
Types of files
PPTX
File Management – File Concept, access methods, File types and File Operation
PDF
File organisation
ODT
Operating System Forensics
PPTX
File System Interface
PDF
Ntfs forensics
PDF
Workshop 2 revised
PPTX
Operating Systems - File Management
PDF
10 File System
PPTX
physical file system in operating system
PPT
Files concepts.53
PPT
File Management in Operating Systems
PPT
Contigious
PDF
File management
file system in operating system
Free Space Management, Efficiency & Performance, Recovery and NFS
11. Storage and File Structure in DBMS
File management
Types of files
File Management – File Concept, access methods, File types and File Operation
File organisation
Operating System Forensics
File System Interface
Ntfs forensics
Workshop 2 revised
Operating Systems - File Management
10 File System
physical file system in operating system
Files concepts.53
File Management in Operating Systems
Contigious
File management
Ad

Similar to File carving overview (20)

PDF
De-Anonymizing Live CDs through Physical Memory Analysis
PPTX
Unit 5.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
PDF
Technical Presentation
PPTX
Operating system note of File System chapter .pptx
PPT
PPT
Windowsforensics
PPT
File Allocation Methods.ppt
PDF
Week7-slides
PDF
Poking The Filesystem For Fun And Profit
PPTX
4_5800969115594131708.pptx
PPTX
File System.pptx
PPTX
C) ICT Application
PDF
Week7 homework
PDF
Week7 homework.pptx
PPTX
Operating System Unit 4(RTU Syllabus).pptx
PPTX
PPTX
Assignment c
PPTX
UNIT III.pptx
PPTX
L12 slides
PPTX
Unit-1-Lecture-9.pptx file structure semester
De-Anonymizing Live CDs through Physical Memory Analysis
Unit 5.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Technical Presentation
Operating system note of File System chapter .pptx
Windowsforensics
File Allocation Methods.ppt
Week7-slides
Poking The Filesystem For Fun And Profit
4_5800969115594131708.pptx
File System.pptx
C) ICT Application
Week7 homework
Week7 homework.pptx
Operating System Unit 4(RTU Syllabus).pptx
Assignment c
UNIT III.pptx
L12 slides
Unit-1-Lecture-9.pptx file structure semester
Ad

More from Marco Alamanni (6)

ODP
Introduction to memory forensics
ODP
Extracting and analyzing browser,email and IM artifacts
ODP
Introduction to forensic imaging
ODP
Brief introduction to digital forensics
PPT
Oracle Database Vault
PDF
Trust:concetti generali e teoria formale
Introduction to memory forensics
Extracting and analyzing browser,email and IM artifacts
Introduction to forensic imaging
Brief introduction to digital forensics
Oracle Database Vault
Trust:concetti generali e teoria formale

Recently uploaded (20)

DOCX
Greta — No-Code AI for Building Full-Stack Web & Mobile Apps
PPTX
Advanced SystemCare Ultimate Crack + Portable (2025)
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Salesforce Agentforce AI Implementation.pdf
PDF
CCleaner Pro 6.38.11537 Crack Final Latest Version 2025
PDF
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
PDF
Tally Prime Crack Download New Version 5.1 [2025] (License Key Free
PDF
AutoCAD Professional Crack 2025 With License Key
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
Designing Intelligence for the Shop Floor.pdf
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
iTop VPN Free 5.6.0.5262 Crack latest version 2025
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PPTX
assetexplorer- product-overview - presentation
PDF
Digital Systems & Binary Numbers (comprehensive )
PPTX
Why Generative AI is the Future of Content, Code & Creativity?
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PDF
17 Powerful Integrations Your Next-Gen MLM Software Needs
PDF
Download FL Studio Crack Latest version 2025 ?
PDF
Odoo Companies in India – Driving Business Transformation.pdf
Greta — No-Code AI for Building Full-Stack Web & Mobile Apps
Advanced SystemCare Ultimate Crack + Portable (2025)
Design an Analysis of Algorithms II-SECS-1021-03
Salesforce Agentforce AI Implementation.pdf
CCleaner Pro 6.38.11537 Crack Final Latest Version 2025
iTop VPN 6.5.0 Crack + License Key 2025 (Premium Version)
Tally Prime Crack Download New Version 5.1 [2025] (License Key Free
AutoCAD Professional Crack 2025 With License Key
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
Designing Intelligence for the Shop Floor.pdf
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
iTop VPN Free 5.6.0.5262 Crack latest version 2025
Navsoft: AI-Powered Business Solutions & Custom Software Development
assetexplorer- product-overview - presentation
Digital Systems & Binary Numbers (comprehensive )
Why Generative AI is the Future of Content, Code & Creativity?
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
17 Powerful Integrations Your Next-Gen MLM Software Needs
Download FL Studio Crack Latest version 2025 ?
Odoo Companies in India – Driving Business Transformation.pdf

File carving overview

  • 1. Digital forensics with Kali Linux Marco Alamanni Section 4 File carving and data recovery www.packtpub.com
  • 2. In this Section, we are going to take a look at… ● Introduction to file carving: unallocated and slack disk space, deleted files, Recycle Bin. ● File carving tools: Foremost, Scalpel and Photorec. ● Data extraction using Bulk-extractor
  • 3. Course Name Author Name Video 4.1 File carving overview
  • 4. In this Video, we are going to take a look at… ● Introduction to file slack and unallocated space, deleted files and the file carving process. • The Windows Recycle Bin and how to examine it with Rifiuti2.
  • 5. Introduction to slack space ● Smallest addressable data units on filesystems are called blocks or clusters, that are usually 4 KB of size. • Files generally use various blocks, the last block being only partial ly used. • The space left between the end of the file’s data and the end of the block is called slack space. • Slack space can contain hidden data or remnants from previously deleted file.
  • 7. Deleted files and unallocated space ● When a file is deleted, the relative directory entry is removed but the entry in the file’s table remains. • The file’s allocated blocks become unallocated; they are marked as free but not modified until reallocated to other files. • The unallocated blocks’ contents could be recovered using The Sleuth Kit tools or data carving tools
  • 8. Introduction to data carving ● Data carving is the process of identifying and extracting meaningful data out of the unallocated and slack space. • It relies on locating the magic number of a file and copying all the data until the end of file (EOF) marker is not found. • It is straightforward if the file’s data blocks are contiguous, could be challenging if the file is fragmented. • Algorithm for file carving that also handle fragmentation has been developed for data carving tools.
  • 9. The Windows Recycle Bin ● On modern operating systems, deleted files are usually first moved to the Recycle Bin (on Windows) or analogous directory. • These files are permanently deleted if the Recycle Bin is emptied or can be restored in the original location. • On Windows XP and earlier deleted files are placed under C:Recycler subfolders, one for each user, and the relative information are stored in INFO2 index files. • On Windows Vista and newer deleted files are stored under C:$Recycle.Bin subfolders in files that begin with $I and $R.