官术网_书友最值得收藏!

  • Windows Forensics Cookbook
  • Oleg Skulkin Scar de Courcier
  • 225字
  • 2021-07-02 20:57:48

How to do it...

Before you start, it's a good idea to find the right data source. ReFS is an active development, and is used usually on Windows servers only. Thankfully, Willi Ballenthin has created a bunch of ReFS images for testing purposes, which are now publically available. Let's use one of them.

  1. Start ReclaiMe File Recovery. It takes some time for the tool to scan all available drives. After this, you will be taken to the main window, like the one in the following figure:
Figure 4.13. ReclaiMe File Recovery main window

ReclaiMe File Recovery doesn't support E01 images, but this is not a problem because we have an image in RAW format.

  1. Let's go to Disks - Open disk image... Choose the disk image and click Open. Now there should also be an image in the main window, like the one in the following figure:

Figure 4.14. ReclaiMe File Recovery main window (Disk image is added)
  1. Double-click the image to start the recovery process. Of course, it will take some time, depending on the size of the image. In our case, the image is small enough, so it doesn't take a lot of time. The recovery is shown in the following figure:
Figure 4.15. ReclaiMe File Recovery image processing results
  1. Now you can save recovered files or even folders using the blue Save button.
主站蜘蛛池模板: 余姚市| 玉龙| 偏关县| 明光市| 青海省| 株洲市| 普陀区| 岑溪市| 乌兰察布市| 峨眉山市| 台山市| 蛟河市| 开平市| 永登县| 延川县| 油尖旺区| 济宁市| 北海市| 韶关市| 三门峡市| 图木舒克市| 曲阜市| 汕尾市| 孟津县| 都江堰市| 普安县| 卫辉市| 永定县| 辰溪县| 巢湖市| 乡宁县| 土默特左旗| 洛阳市| 二连浩特市| 古浪县| 竹溪县| 海伦市| 定边县| 万安县| 甘孜县| 托克托县|