O'Reilly logo

Windows Forensics Cookbook by Scar de Courcier, Oleg Skulkin

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

How to do it...

Open Windows Command Prompt and change the directory to bin (you can find it in the folder where you unpacked the archive you downloaded). Let's start from the Media Management Layer Tools:

  1. The first thing you should do is to figure out which system volume type you have. Of course, there is a tool for this in The Sleuth Kit. It's called mmstat. Let's use it on one of the images we acquired in the previous recipes:
mmstat X:146-2017.E01
Figure 4.1. mmstat output
  1. We now know the system volume type and are ready to use the next tool mmls. This tool can help an examiner to determine the layout of a disk, including the unallocated ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required