How to do it...

Open Windows Command Prompt and change the directory to bin (you can find it in the folder where you unpacked the archive you downloaded). Let's start from the Media Management Layer Tools:

  1. The first thing you should do is to figure out which system volume type you have. Of course, there is a tool for this in The Sleuth Kit. It's called mmstat. Let's use it on one of the images we acquired in the previous recipes:
mmstat X:146-2017.E01
Figure 4.1. mmstat output
  1. We now know the system volume type and are ready to use the next tool mmls. This tool can help an examiner to determine the layout of a disk, including the unallocated ...

Get Windows Forensics Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.