Disk forensics techniques are used to acquire the disk image, process this image to find artifacts of interest including deleted ones.
In this lab, a disk image file “evidence.img” is provided in the home directory of the root user (/root/). Interact with the image using The Sleuth Kit and answer the following questions:
The solution for this lab can be found in the following manual: https://assets.ine.com/labs/ad-manuals/walkthrough-1790.pdf