Recovering deleted files with DFF

For this exercise, we'll be using a very small .raw image created using DD. This file is approximately 6 MB and is publicly available at http://dftt.sourceforge.net/test7/index.html:

  1. Click on the ZIP file to download it and extract it to its default location. When extracted, the name of the file shows up as 7-ntfs-undel.dd. Using the preceding steps, start DD if you haven't yet opened the program. Before we import the image, take a moment to observe the icons next to the entries in the main window area. The icon for the Logical files field is a white folder with a hint of blue:
When we add an image in the ...

Get Digital Forensics with Kali Linux now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.