Q: 18
A digital forensic investigator is tasked with analyzing an NTFS image file extracted from a pen drive.
They leverage The Sleuth Kit (TSK) for this task, specifically utilizing the fsstat command-line tool. By
employing fsstat, they delve into the file system’s intricate details, such as metadata, inode numbers,
and block or cluster information, thereby facilitating a comprehensive examination.
How can an investigator use TSK to analyze disk images?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.