When a shell is not enough
Thursday, October 7, 2010
LUKS encrypted disk forensics
Sans Computer Forensics
shows how to perform forensics investigations in a disk image that contains
The following tricks appear in the article:
Use 'losetup' to create a read-only logical device pointing to the LUKS partition.
Use 'cryptsetup' to verify that the partitions is LUKS and then mount it.
LVM2 Fu to load/unload the Volum Groups
Thursday, October 07, 2010
Share to Twitter
Share to Facebook
Share to Pinterest
Post a Comment
Post Comments (Atom)