SleuthKit

This kinda tools really amazes me lol :slight_smile:

Download:


PENGUIN Sleuth Kit Bootable CD

Download:

http://www.linux-forensics.com/downloads.html

Regards.

Basically they use their own filesystem driver… not revolutionary, every data recovery s/w does that, so why did you make that bold..

The question is (if u have used it u can answer), what other info does it provide?

I was just wondering who wrote the first “revolutionary” guide on Kernel compiling, by any chance was it you KK :slight_smile: I doubt what google has to say with his thousands of search results for it :wink:

Regards.

revolutionary? My guide?? I am laughing as much as you on that one…

I just don’t understand why u made that bold… u seemed excited, even tho your team made the only crack for GDB… so you do know what this kind of software does. Maybe you wanted to put some emphasis on it, but I don’t see why. I am not against the post, just the boldface placement.

I really do want to know - what other tools does it provide? Data recovery is old stuff, they must have something else to justify the s/w. Cos u often hear of forensic tools such as this, but I have never come across one that is openly available, so if you have experience with this tool, tell me so I cn decide whether to dld that live cd

how does the software work???

Work regarding which feature?

hey can GDB analyse files from ext3,UFS(solaris) filesystems ,N0!? Actually I had successfully used R-Linux to once recover data from my lost ext3 partition

Do u find this interesting;

http://www.sleuthkit.org/sleuthkit/docs/ref_fs.html

Regards.

Now that is more like it.

There was a tool from GRC too for data recovery including FAT,NTFS and ext