DIGITAL FORENSIC
1 IDENTIFICATION
2 PERESERVATION
- chain of custoday
- Labeling
-imaging/Clone(membuat kmbarannya)
3 EXAMINATION (pengujian)
4 ANALYSIS
5 REPORTING/PRODUCK
APLIKASI YG BIASA D GUNAKAN
a.(TESDISK)
b.(AUTOPSY) biasa d buka d brouser.
2 PERESERVATION
- chain of custoday
- Labeling
-imaging/Clone(membuat kmbarannya)
3 EXAMINATION (pengujian)
4 ANALYSIS
5 REPORTING/PRODUCK
APLIKASI YG BIASA D GUNAKAN
a.(TESDISK)
b.(AUTOPSY) biasa d buka d brouser.
┌─[budhya@parrot]─[~]
└──╼ $sudo
su
[sudo] password for
budhya:
┌─[root@parrot]─[/home/budhya]
└──╼
#apt-get install testdisk
Reading package
lists... Done
Building dependency
tree
Reading state
information... Done
The following NEW
packages will be installed:
testdisk
0 upgraded, 1 newly
installed, 0 to remove and 151 not upgraded.
Need to get 394 kB
of archives.
After this
operation, 1,419 kB of additional disk space will be used.
Get:1
http://eu.repository.frozenbox.org/mirrors/debian/ jessie/main
testdisk i386 6.14-3+b2 [394 kB]
Fetched 394 kB in 3s
(104 kB/s)
Selecting previously
unselected package testdisk.
(Reading database
... 269039 files and directories currently installed.)
Preparing to unpack
.../testdisk_6.14-3+b2_i386.deb ...
Unpacking testdisk
(6.14-3+b2) ...
Processing triggers
for man-db (2.7.0.2-5) ...
Setting up testdisk
(6.14-3+b2) …
┌─[root@parrot]─[/home/budhya]
└──╼
#testdisk /dev/sdb
TestDisk 6.14, Data
Recovery Utility, July 2013
Christophe GRENIER
<grenier@cgsecurity.org>
http://www.cgsecurity.org
┌─[root@parrot]─[/home/budhya]
└──╼
#testdisk /dev/sdb
the disk is name TOSHIBA andthan you (ENTER) next you seleck a intel partision and (ENTER)
Next you seleck ANALYSE And ENTER
Next you seleck again QUICK SEARCH And ENTER
Next seleck CONTINUE (ENTER)
The next you seleck (P) p is is for (list file) for looking your file in direcktory
the next is RED FILE in a direck tory this is a file target and copy you mas seleck (C) In a Red file
next selec cofy again is finished cofy is list green copy done
and search in your pc for paste after copy your file in your list red directory
and seach from deroctory pc the last paste after copy and finis
Tidak ada komentar:
Posting Komentar