Question: Begin a scripting session (remember to append your log if you close and reopen the Terminal). Download the Rhino Hunt zip archive from the CFREDS
Begin a scripting session (remember to append your log if you close and reopen the Terminal). Download the Rhino Hunt zip archive from the CFREDS website on the Data Sets page using the "wget" command to a folder you created named Linux_Carving. Hash the zip file prior to extraction and compare it to the MD5 hash value listed provided. o See the Team Drive for the .zip file hash. Perform typical evidence preservation techniques and compare hash values from all copies made. Perform a hash value calculation of the .dd image inside the zip file and compare it to the value provided on the website (viewing of the MD5 value on the website can be done through the GUI browser). Create a copy of the Scalpel configuration file and direct the copy to your Desktop. Using vim, edit the copy of the Scalpel config file to uncomment file type lines for jpg, png, bmp, gif and doc files. Run Scalpel on RHINOUSB.dd and output the carved files to the directory Scalpel_Results. o Remember to indicate the location of your new configuration file copy in your command. Run Foremost on RHINOUSB.dd for the file types jpg, png, bmp, gif and doc and output the carved files to the directory Foremost_Results. Automated Carving Lab 7 Run ssdeep to compare the content of the directories Scalpel_Results and Foremost_Results and redirect the output of the command to a text file named Hash_Comparison.txt. Display the content of Hash_Comparison.txt in the Terminal. Report the names of any file combinations that indicate a 100% match.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
