[sleuthkit-users] Wrong results when reading System Volume Shadow Files
Brought to you by:
carrier
From: Luís F. N. <lfc...@gm...> - 2014-10-06 01:47:11
|
Hi, We are getting incorrect results with sleuthkit 4.1.3 and 4.2.0 when reading the contents of a lot of windows volume shadow copy files from many disk images. The contents of these files are being reported as zeroed files by sleuthkit. But they are not zeroed files, as reported by other forensic tools. So we are not being able to carve these files using sleuthkit. If we can provide more info to help addressing the issue, please let us know. Any help will be appreciated, Luis Nassif |