There two tools might come in handy, I learned about them from project.honeynet.org
They are
TASK (The @stake Sleuth Kit) and Autopsy (graphical frontend to TASK)
It does involve some knowledge about file-headers though.
TASK can be found @ http://www.atstake.com/research/tools/task/index.html
Autopsy @ http://www.atstake.com/research/tool...psy/index.html
TASK is a collection of open source, command line tools based on The
Coroner's Toolkit (TCT) and TCTUTILs. Using these tools, an investigator
can view the details of NTFS, FAT, FFS, and EXT2FS file systems.
TASK gives an investigator access to details that other tools do not,
which can be used for advanced file recovery. TASK is the only open
source collection of tools for both Windows and UNIX file systems that
allow one to view both allocated and unallocated files.




Reply With Quote