File analysis with DFF

Now that we've looked at the file recovery process, let's continue our investigation with DFF by examining an image file with more content.

For this exercise, we will be using another publicly available image called the JPEG Search Test #1 (Jun '04). The ZIP file can be downloaded at

  1. After downloading the ZIP file, extract it to its default location. The name of the decompressed file is 8-jpeg-search.dd.
  2. Open the evidence file in DFF by repeating the steps in the preceding exercise:
    1. Start DFF by clicking on ApplicationsForensics | ddf gui.
    2. Click on the Open evidence button.
    3. Browse to the 8-jpeg-search.dd image file (as seen in the following screenshot).
    1. Click OK: ...

Get Digital Forensics with Kali Linux now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.