In this video we will use tsk_recover to carve a physical disk image of a suspect drive stored on our forensic workstation. tsk_recover is a command-line tool for recovering various types of data for forensic purposes.
The Sleuthkit (tsk_recover): http://www.sleuthkit.org/sleuthkit/
🚀 Full Digital Forensic Courses → https://learn.dfir.science
010001000100011001010011011000110110100101100101011011100110001101100101
Get more Digital Forensic Science
👍 Subscribe → https://bit.ly/2Ij9Ojc
❤️ YT Member → https://bit.ly/DFIRSciMember
❤️ Patreon → https://www.patreon.com/dfirscience
🕸️ Blog → https://DFIR.Science
🤖 Code → https://github.com/DFIRScience
🐦 Follow → https://www.twitter.com/DFIRScience
📰 DFIR Newsletter → https://bit.ly/DFIRNews
010100110111010101100010011100110110001101110010011010010110001001100101
Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. Please link back to the original video. If you want to use this video for commercial purposes, please contact us first. We would love to see what you are doing.