Digital Forensics
Due by start of class Tuesday, March 3

Extracting differential data from two filesystem images

Please examine the files filesys2 and filesys3 using the same base set of tools specified in assignment 2 (you are of course welcome to augment these tools with any that you would like.)

These are two snapshots of the same filesystem, taken within minutes of each other.

These are the levels of data extraction that I would like to see in your answer:

  1. What kind of filesystems are these and what are their general characteristics?
  2. What are the current contents of this filesystem, including filenames, directory names, and data in files?
  3. What are the deleted contents of this filesystem, including filenames, directory names, and any recoverable data in files?
  4. What changed in the intervening period between these two snapshots?

Your Work Product:

Please turn in your answers to the four above questions on paper on Tuesday, March 3, at the beginning of class.