The Foremost Open Source Forensic Tool
By Ray Strubinger, August 06, 2003
Several open source forensic tools have been created for the Unix platform; most notably, The Coroner's Toolkit (TCT) by Dan Farmer and Wietse Venema, as well as The @stake Sleuth Kit (TASK) and its browser-based front end, Autopsy, both created by Brian Carrier. While TCT and TASK/Autopsy have been written about frequently, there is another very useful application known as "foremost" that has received relatively little attention outside of a few computer forensics mailing lists.
Figure 4 An excerpt from a foremost audit.txt file
File Found at Byte Interior Length Extracted From
00000000.pdf 530647127 X 100000 ext2-home.dd
00000001.htm 573793842 X 1862 ext2-home.dd
00000002.htm 573795890 X 2496 ext2-home.dd
00000003.htm 573963826 X 50000 ext2-home.dd
00000004.jpg 618702753 X 32537 ext2-home.dd
00000005.jpg 619379429 X 45094 ext2-home.dd
00000006.htm 624262656 11705 ext2-home.dd
00000007.htm 624279040 7152 ext2-home.dd