Disk forensics techniques are used to acquire the disk image, process this image to find artifacts of interest including deleted ones.
In this lab, a disk image file “evidence.img” is provided in the home directory of the root user (/root/). One of the PDF files present on the disk contains the flag.
Objective: Extract files from the given image using Scalpel tool and retrieve the flag!
Guidelines:
The solution for this lab can be found in the following manual: https://assets.ine.com/labs/ad-manuals/walkthrough-1792.pdf