EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium
A forensic investigator is analyzing a Linux system after a suspected breach. They notice that the attacker attempted to remove their tracks by deleting critical log files and modifying timestamps. Which file system utility could help the investigator recover deleted files or at least identify remnants of the attacker's activity by examining the raw disk image?
- Als -al
- Bstrings
- Cforemost
- Dgrep
Show answer & explanationAnswer & explanation
Correct answer: C. foremost
Foremost is a forensic data carving tool specifically designed to recover files based on their headers, footers, and internal data structures from disk images. While 'strings' might find readable text, and 'grep' could search existing files, only a carving tool like Foremost is effective for recovering deleted files from raw disk images.
Why the other options are wrong
- A. ls -al lists directory contents and file attributes, but doesn't recover deleted data.
- B. strings extracts printable character sequences from binary files, which might reveal remnants but won't recover full deleted files.
- D. grep is used to search for text patterns within existing files, not to recover deleted files.
Data Carving (Foremost)
The process of extracting files or fragments of files from raw data (like a disk image) based on their file type headers, footers, and internal data structures, even if the file system metadata has been deleted.
- Foremost is a popular open-source tool for data carving.
- Useful for recovering deleted files from compromised systems.
- Works on raw disk images or directly on devices.
Memory trick: Recover files: Carving for deleted, Grep for text, Strings for binary, ls for existing.