How to do it...

We use the following methodology to accomplish our objective:

  1. Identify if the evidence container is a raw image or an E01 container.
  2. Access the image using pytsk3.
  3. Recurse through all directories in each partition.
  4. Send each file to be hashed using the appropriate hashing algorithm.
  5. Check if the hash matches one of those provided and if so, print to the console.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.223.124.244