CY484- Digital Forensics LABORATORY
Lab 5: File Carving
This lab is designed to be conducted on Windows operating system. Throughout this lab,
you will complete three key activities that are essential for digital forensics:
Activity 1: File carving using FTK Imager
Activity 2: File Carving with Carver Recovery
Activity 3: Data Recovery with Bulk Extractor
Tools:
1. FTK Imager
2. Carver Recovery
3. Bulk Extractor
, 2
CY484- Digital Forensics LABORATORY
Lab 5: File Carving
Activity 1: File carving using FTK Imager
In this activity you will perform manual file carving using FTK Imager.
Instructions:
STEP 1. Download and install FTK Imager.
STEP 2. Download the file named “raw_image2.dd” from the e-learning portal.
STEP 3. Launch FTK Imager.
STEP 4. From the main menu select “File” and the select “Add Evidence Item…”
STEP 5. In the “Select Source” dialog box select the radio button next to “Image File” and
then click the “Next” button.
STEP 6. Browse to the file named “raw_image2.dd” and open the file. FTK Imager will
display the file as shown in the Figure below.