Back to Search Start Over

Using open source forensic carving tools on split dd and EWF files

Authors :
Gareth Palmieri
Shahrzad Zargari
Source :
iThings/GreenCom/CPSCom/SmartData
Publication Year :
2017
Publisher :
IEEE, 2017.

Abstract

This study tests a number of open source forensic\ud carving tools to determine their viability when run across split raw\ud forensic images (dd) and Expert Witness Compression Format\ud (EWF) images. This is done by carving files from a raw dd file to\ud determine the baseline before running each tool over the different\ud image types and analysing the results. A framework is then written\ud in python to allow Scalpel to be run across any split dd image,\ud whilst simultaneously concatenating the carved files and sorting by\ud file type. This study tests the framework on a number of scenarios\ud and concludes that this is an effective method of carving files using\ud Scalpel over split dd images.

Details

Language :
English
ISBN :
978-1-5386-3066-2
ISBNs :
9781538630662
Database :
OpenAIRE
Journal :
iThings/GreenCom/CPSCom/SmartData
Accession number :
edsair.doi.dedup.....85836b166dcb9509d2dde7fe8a660251