Abstract
During a computer forensics investigation we faced a problem how to get all the interesting files we need fast. We work, mainly, using the Open Source software products and Linux OS, and we consider the Sleuthkit and the Foremost two very useful tools, but for reaching our target they were too complicated and time consuming to use. For this reason we developed the Selective File Dumper, a Linux Bash script which makes it possible to extract all the referenced, deleted and unallocated files and finally to perform a keyword search, in a simple way.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
References
Carrier B (2005) File System Forensics Analysis. Addison Wesley Professional
Ghirardini A, Faggioli G (2007) Computer Forensics. Apogeo
Newman RC (2007) Computer Forensics. Auerbach Pubblications
Mandia K, Prosise C (2002) Hacker Pronto Intervento. Apogeo
Nolan R, O’Sullivan C, Branson J, Waits C (2005) First Responders Guide to Computer Forensics. CERT Training and Education
Solomon MG, Barrett D, Broom N (2005) Computer Forensics JumpStart. Sybex
Autopsy and Sleuthkit. The Digital Forensics Toolkit. The Tracker Dog’s Guide www.linux-magazine.com/issue/36/Autopsy.pdf
Linux Kubuntu/Ubuntu - http://www.kubuntu.org http://www.ubuntu.com
Sleuthkit - http://www.sleuthkit.org
Foremost - http://foremost.sourceforge.net
Sha256deep - http://md5deep.sourceforge.net/
Bash Guide - http://tldp.org/LDP/abs/html/
Zenity - http://freshmeat.net/projects/zenity
Sourceforge - http://sourceforge.net
Wikipedia - http://en.wikipedia.org/wiki/Open_source
Bash Cookbook - Carl Albing, JP Vossen, Cameron Newham - O’Reilly - 2007
Producing Open Source Software: How to Run a Successful Free Software Project -Karl Fogel - O’Reilly - Paperback 2005
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2010 Springer Science+Business Media, LLC
About this paper
Cite this paper
Bassetti, N., Frati, D. (2010). Selective File Dumper. In: Huebner, E., Zanero, S. (eds) Open Source Software for Digital Forensics. Springer, Boston, MA. https://doi.org/10.1007/978-1-4419-5803-7_8
Download citation
DOI: https://doi.org/10.1007/978-1-4419-5803-7_8
Published:
Publisher Name: Springer, Boston, MA
Print ISBN: 978-1-4419-5802-0
Online ISBN: 978-1-4419-5803-7
eBook Packages: Computer ScienceComputer Science (R0)