Recovering deleted files with SleuthKit
SleuthKit is probably one of the most comprehensive collections of tools for forensic filesystem analysis. One of the most basic use-cases is the recovery of files that have been deleted. However, SleuthKit can do much, much more. Have a look at the case studies wiki page for an impression. Let’s assume, there is a FAT volume on our disk (maybe… Read more »