Re: [sleuthkit-users] Directory extraction
Brought to you by:
carrier
From: M77 <m7...@li...> - 2011-06-30 21:10:03
|
Thanks, but I need to extract full tree of directories with files inside. For this case I'm back to use my usual software. Il 27.06.2011 14:44, Grundy Barry J TIGTA ha scritto: > > You can also use sorter and pass it a directory meta data address and > have it extract and categorize files from just that directory. > > /******************************************* > Barry J. Grundy > Assistant Special Agent in Charge > Digital Forensic Support Group > Electronic Crimes and Intelligence Division > Treasury Inspector General for Tax Administration > (301) 210-8741 (w) > (202) 527-5778 (c) > Bar...@ti... > ********************************************\ > > *From:*slo...@gm... [mailto:slo...@gm...] > *Sent:* Sunday, June 26, 2011 6:43 PM > *To:* M77 > *Cc:* sle...@li... > *Subject:* Re: [sleuthkit-users] Directory extraction > > tsk_recover will recover all the files in an image. You can specify > only allocated, only unallocated, or both. You cannot limit > tsk_recover to a specific directory, only a specific volume. > > On Sun, Jun 26, 2011 at 11:58 AM, M77 <m7...@li... > <mailto:m7...@li...>> wrote: > > Hi, It's possible to extract a directory tree, (and files inside) > recovered analyzing one dd hard disk image using autopsy? > > Thanks > > m1001101 > > > ------------------------------------------------------------------------------ > All of the data generated in your IT infrastructure is seriously valuable. > Why? It contains a definitive record of application performance, security > threats, fraudulent activity, and more. Splunk takes this data and makes > sense of it. IT sense. And common sense. > http://p.sf.net/sfu/splunk-d2d-c2 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |