DIGITAL FORENSIC
1 IDENTIFICATION
2 PERESERVATION
- chain of custoday
- Labeling
-imaging/Clone(membuat kmbarannya)
3 EXAMINATION (pengujian)
4 ANALYSIS
5 REPORTING/PRODUCK
APLIKASI YG BIASA D GUNAKAN
a.(TESDISK)
b.(AUTOPSY) biasa d buka d brouser.
2 PERESERVATION
- chain of custoday
- Labeling
-imaging/Clone(membuat kmbarannya)
3 EXAMINATION (pengujian)
4 ANALYSIS
5 REPORTING/PRODUCK
APLIKASI YG BIASA D GUNAKAN
a.(TESDISK)
b.(AUTOPSY) biasa d buka d brouser.
┌─[budhya@parrot]─[~]
└──╼ $sudo
su
[sudo] password for
budhya:
┌─[root@parrot]─[/home/budhya]
└──╼
#apt-get install testdisk
Reading package
lists... Done
Building dependency
tree
Reading state
information... Done
The following NEW
packages will be installed:
testdisk
0 upgraded, 1 newly
installed, 0 to remove and 151 not upgraded.
Need to get 394 kB
of archives.
After this
operation, 1,419 kB of additional disk space will be used.
Get:1
http://eu.repository.frozenbox.org/mirrors/debian/ jessie/main
testdisk i386 6.14-3+b2 [394 kB]
Fetched 394 kB in 3s
(104 kB/s)
Selecting previously
unselected package testdisk.
(Reading database
... 269039 files and directories currently installed.)
Preparing to unpack
.../testdisk_6.14-3+b2_i386.deb ...
Unpacking testdisk
(6.14-3+b2) ...
Processing triggers
for man-db (2.7.0.2-5) ...
Setting up testdisk
(6.14-3+b2) …

┌─[root@parrot]─[/home/budhya]
└──╼
#testdisk /dev/sdb
TestDisk 6.14, Data
Recovery Utility, July 2013
Christophe GRENIER
<grenier@cgsecurity.org>
http://www.cgsecurity.org
┌─[root@parrot]─[/home/budhya]
└──╼
#testdisk /dev/sdb
the disk is name TOSHIBA andthan you (ENTER) next you seleck a intel partision and (ENTER)
Next you seleck ANALYSE And ENTER
Next you seleck again QUICK SEARCH And ENTER
Next seleck CONTINUE (ENTER)
The next you seleck (P) p is is for (list file) for looking your file in direcktory
the next is RED FILE in a direck tory this is a file target and copy you mas seleck (C) In a Red file
next selec cofy again is finished cofy is list green copy done

and seach from deroctory pc the last paste after copy and finis
Tidak ada komentar:
Posting Komentar