File carving with PhotoRec
PhotoRec is a file carving tool that is widely used by digital forensic examiners. This tool is even built into the previously mentioned digital forensic platform, Autopsy, as a module. PhotoRec can recover a diverse range of file types (more than 480 file formats), but if you think this will not be enough, you can add your own custom signatures, which will help the tool to recover even more data.
Getting ready
Go to CGSecurity's website and click the download
hyperlink on the left. You will be redirected to the Download page. Now click on the big green button on the right, and the downloading process will be initiated. At the time of writing, the most recent version of PhotoRec is 7.0, so the archive we downloaded is called testdisk-7.0.win.zip. Unpack it and you are ready to go.
How to do it...
Before we start, it's important to note that PhotoRec supports disk images: not only RAW, but also E01. As we are carving data for forensic purposes, let's use an E01 image...