![]() |
|
Computer Forensics - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: General (https://sinister.ly/Forum-General) +--- Forum: The Lounge (https://sinister.ly/Forum-The-Lounge) +--- Thread: Computer Forensics (/Thread-Computer-Forensics) Pages:
1
2
|
RE: Computer Forensics - Magnetron - 05-29-2019 (05-28-2019, 04:38 PM)Sartux Wrote:(05-21-2019, 06:29 AM)Magnetron Wrote: Forensics can still be useful in the event of a crash or accidentally deleting your own stuff, however.That's damn impressive. Good work. I mainly used X-Ways Forensics (Winhex) coupled with a bunch of other apps to assist me such as TestDisk to help identify partition metadata and a bunch more smaller apps and scripts for miscellaneous stuff that came along the way. Putting fragmented files back together may rank as the most annoying task ever in data recovery. RE: Computer Forensics - urgodfather - 06-24-2019 TestDisk is by far one of the best I have used for file/partition recovery provided it wasn't written over. For extensive Data Recovery, there is no "one tool fits all." For example, let's say you have a mechanical drive that is failing or has failed. Here is the most important thing to do that so many IT Specialists overlook. If it mounts, CLONE IT! Don't just jump in to Data Recovery on it! Think like you're driving down the road on a flat tire. The more you drive on it, the more damage. There are plenty of cloning utilities out there. Some will work well in one case but not the other. It varies. Once you get a clone, NOW you reconstruct it. Again, different tools for different circumstances. It never hurts to make backup clones too. This way you have viable restore points if you decide to manually reconstruct. So, let's say it doesn't mount... now what? This is crossing into hardware (occationally software) hacking, and also applies to thumbsticks, ssd's, etc. You will need to RE the circuitry and identify the problem. It could be a bad chip, crystal, resistor, or even full on mechanical failure. Familiarize yourself with it. Then look for viable workarounds. Repair whats needed, then RAW clone it to a donor for reconstruction. You may have to dive even deeper into byte level reconstruction. Having the right tools is everything. Soldering tools, Forensic tools, Oscilators, Programmers, Null Modem cables, THESE ARE ALL YOUR FRIENDS. RE: Computer Forensics - Tivoli - 08-21-2020 Glad to see such themes, good stuff. Memory forensics is the way, the law enforcement would go if your system is encrypted. There are methods exists, which allow them to image your memory and grab the encryption keys, which could decrypt your data. Even if you have unbreakable password, all encryption keys are resides in memory. If your encrypted PC is powered on when the guests have come, then you're in trouble. RE: Computer Forensics - taylostolo - 08-21-2020 (08-21-2020, 09:37 PM)Tivoli Wrote: Glad to see such themes, good stuff.dont wake the dead their sleeping. RE: Computer Forensics - Tivoli - 08-21-2020 (08-21-2020, 09:55 PM)taylostolo Wrote:(08-21-2020, 09:37 PM)Tivoli Wrote: Glad to see such themes, good stuff.don't wake the dead their sleeping. I'm sorry, but I think people should know about such attack vector. If theme is exhausted, there is no need to discuss it, but this information people should be aware of. Give me your OS memory dump, and we will try to find out who you are :-) RE: Computer Forensics - taylostolo - 08-22-2020 (08-21-2020, 10:15 PM)Tivoli Wrote:yes people should know about mem forensics so make a new post and type your heart away...(08-21-2020, 09:55 PM)taylostolo Wrote:(08-21-2020, 09:37 PM)Tivoli Wrote: Glad to see such themes, good stuff.don't wake the dead their sleeping. im quite alright whe it comes to the dump im a very private person and my signature gives you all the info you need im the librarian so relax your inner keyboard warrior.
|