Forensic

Saturday 14 December 2019, 20:07  #1
Forensic - Job Interview
natryvat
  • 2 posts

Can anyone help me? I downloaded the .zip file of this challenge and extrected it, buy when I try to import it to autopsy, the file format can’t be recognized, how can I import it o which tool could I use?

Saturday 14 December 2019, 20:14  #2
Forensic - Job Interview
NonStandardModel
  • 42 posts

When I do not know the type of file I run always the same command ... file :)

Saturday 14 December 2019, 21:15  #3
Forensic - Job Interview
natryvat
  • 2 posts

I thought the same, it’s a "EWF/Expert Witness/EnCase image file format", but autopsy could’t determine the volume system type for the disk image, I tried add the image file as disk and as a volume image type

Saturday 14 December 2019, 21:51  #4
Forensic - Job Interview
NonStandardModel
  • 42 posts

I must confess that my notes for this challenge are almost non-existing.
But I seem to remember that by Googling how to open/mount the EWF I got the tool :)
.. but .. it did not work for me on Ubuntu (can’t remember the reason). So I moved to Kali VM, which had the tool already installed.

Thursday 31 December 2020, 14:17  #5
Forensic - Job Interview
Maris
  • 1 posts

duno if it’s too much, but my go-to tool is FTK Imager, after that you can figure out what to do with that file.