Prev Contents Next


Block Hashes

Looking at smaller granularity than files

Hash 512-Byte blocks of the known files

When using dd, can you identify known blocks?
      Yes, on a dd image of NTFS

Use with dcfldd to selectively image?

Can we perform statistic identification of files
      that are dynamic or are variants?

Can we combine this with deleted file recovery to
      focus recovery away from known files?

HUGE amount of data