Now that we've looked at the file recovery process, let's continue our investigation with DFF by examining an image file with more content.
For this exercise, we will be using another publicly available image called the JPEG Search Test #1 (Jun '04). The ZIP file can be downloaded at http://dftt.sourceforge.net/test8/index.html:
- After downloading the ZIP file, extract it to its default location. The name of the decompressed file is 8-jpeg-search.dd.
- Open the evidence file in DFF by repeating the steps in the preceding exercise:
- Start DFF by clicking on Applications | Forensics | ddf gui.
- Click on the Open evidence button.
- Browse to the 8-jpeg-search.dd image file (as seen in the following screenshot).
- Click OK: ...