Category: Host forensics

Recovering a FAT filesystem directory entry in five phases

24 May, 2007 (15:00) | Digital forensics, Forensic tools, Fundamentals, Host forensics | No comments

This is the last in a series of posts about five phases that digital forensics tools go through to recover data structures (digital evidence) from a stream of bytes. The first post covered fundamental concepts of data structures, as well as a high level overview of the phases. The second post examined each phase in [...]