Digital Forensics
Due by start of class Thursday, July 17

Extracting differential data from two filesystem images

Please examine the files filesys2 and filesys3.

These are two snapshots of the same filesystem, taken within minutes of each other.

These are the levels of data extraction that I would like to see in your answer:

  1. What kind of filesystems are these and what are their general characteristics?
  2. What are the current contents of this filesystem, including filenames, directory names, and data in files?
  3. What are the deleted contents of this filesystem, including filenames, directory names, and any recoverable data in files?
  4. What changed in the intervening period between these two snapshots?

Your Work Product:

Please turn in your answers to the four above questions via Blackboard. Please submit a PDF file or a text file.