Aug. 5, 2022, 2:56 p.m. | /u/DeadBirdRugby

Computer Forensics www.reddit.com

Good morning /r/computerforensics


I've got a hypothetical scenario I'd like to run by you -


I've got a Ubuntu VM. Suppose I create a partition, write files to that partition, and then delete the partition. How would I image the VM to obtain the disk slack that contained that partition? Do VMs even contain disk slack?


How about if I have partition sda, sdb, and sdc, aside from the naming convention, if I deleted sdb, any tips on identifying that …

computerforensics forensics linux linux forensics scenario

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Werkstudent (w/m/d) - Cyber Security

@ IONOS | Karlsruhe, Germany

Security Operations Manager

@ BambooHR | Utah | Hybrid

Senior Risk and Compliance Analyst

@ Cricket.com | Hyderabad

Cyber Security Architect

@ Lilium | Munich