How do I do hard drive forensics?
>>62435895
You open up the HDD cover and use a magnet to remove the encryption. Then you reformat the drive with easier to read FAT32.
>>62435895
buy a lot of hardware and software products
>>62435925
>open the cover
I don't have a positive pressure clean room.
>>62435895
run
# dd if=/dev/random of=/dev/sda
>>62436005
it worked thanks
>>62436005
I'm not trying to put a pedo in jail.
>>62436055
good to know :^)
>>62435939
Install a window fan.
>>62435895
Depends on what you're trying to do.
Recovery? Forensic analysis?
>>62435895
Use a LiveCD that supports forensics.
>>62436900
I don't know what's in it.
I just know there was a bunch of corporate data written on it.
>>62437182
That's hardly informative. Is it busted or not?
>>62437312
Not busted, but wiped.
>>62437320
For future reference, this is known as forensic analysis. What happens next largely depends on two factors: if the wipe was up to NIST standards (STFW for "Guttman Wipe") or simply formatted.
I'd use photorec to take a quick look around if you want to do this casually, or you can take the official route of making a proper forensic image.
Choice is yours, really.
>>62435895
install gentoo
>>62437377
Thanks, anon.
>>62437398
Think nothing of it. A bit of knowledge and usable experience here can be nice when applied properly. What a pity it doesn't happen more often.
>>62435895
what ya do, is put the HDD under the microscope and read the data.
>>62437513
Another interested anon here. What is the "official" route? Just clone onto another disk?
>>62437565
In a sense. In forensic acquisition, it is absolutely imperative that the contents of the disk do not become modified while in acquisition, transit or storage. While most would rely on a copy of software like Encase to verify this, I would assume hash sums and a block-for-block copy of the disk may be sufficient.
While working with these forensic images, take great care to throw them through a loopback set as read only- it would be like a detective fudging a crucial piece of evidence in a case!
>>62435895
You need a really good microscope. Preferably an electron microscope to see all the little electrons
>>62435895
The tools off kali worked well. I forget the name of the one I used, but it was able to scan a block device for regex strings (SSN, CCN, etc) :^)
>>62437530
I think u mean telescope