Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/sh
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- fsstat $Image.dd ## fsstat - Displays details about the file system
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- blkcat $Image.dd $BlockNum ## blkcat - Displays the contents of a disk block
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- blkls $Image.dd > $Imagefile.blkls ## blkls - Lists contents of deleted disk blocks
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- blkcalc $Image.dd -u $BlklsNum ## blkcalc - Maps between dd images and blkls results
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- blkstat $Image.dd $ClusterNum ## blkstat - Display allocation status of block
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- istat $Image.dd $InodeNum ## istat - Displays information about a specific inode
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- icat $Image.dd $InodeNum ## icat - Displays contents of blocks allocated to an inode
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- istat /dev/$Disk ## Use The Sleuth Kit to view file informaMon
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- ifind $Image.dd –d $InodeNum ## ifind - Determine which inode contains a specific block
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- ils $Image.dd ## ils - Displays inode details
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- fls -rpd $Image.dd ## fls - Displays deleted file entries in a directory inode
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- ffind $Image.dd $InodeNum ## ffind - Find the filename that using the inode
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
- sigfind $HexValue -o $Offset ## sigfind - search for a binary value at a given offset (-o)
- ## ---------------------------------------------------------------------------------------------------------------------------- ##
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement