CSC 370 - La Salle University

EnCase: List files whose extensions do not match file type (.doc->.jpeg) Sfind: Show hidden or alternative data stream files (www.foundstone.com) Do not use any utilities on the hack machine before all information is saved! Three ways to save forensic data: Save to floppy: [cmd] >> a:\logfile ................
................