Recover removed /var/log directory


banderas20

New Member
Apr 23, 2019
8
Ratings
3
3
#1
Hello,

I am investigating a set of raw dumps from a Linux system. When I mount the dumps, I can't seem to find /var/log directory, neither their files.

It seems it has been removed on purpose.

¿Is there any way to recover them?

I am using Autopsy software, and I can't find anything in removed files nor in Carved files...

Thanks in advance!
 

azuleonyx

Member
Experienced Member
Oct 20, 2018
45
Ratings
39
18
Charlotte, North Carolina Area
cyberfenixtech.blogspot.com
Twitter
https://twitter.com/AzuleOnyx
#4
Well, the issue is: complete disk image or missing empty space. Autospy will show deleted files if it can find them; though, if not, then you'll have to do some different file carving.
 

About us

  • Our community began in 2004. Since this time, we have grown to have over 29,000+ members within the DFIR & Cyber Security community.

    We are happy to announce that this forum is now under new ownership with the goal to once again become the main Digital Forensics Forum on the internet for DFIR, OSINT and Cyber Security.

    If you can think of ways to help us improve, please let us know.

    We pride ourselves on offering unbiased, critical discussion among people of all different backgrounds.

    We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu