1 min read 135 words Updated Sep 12, 2026 Created Sep 12, 2026

Forensics commonly requires inspecting memory dumps or disk images or specific files.

inspecting files

binwalk

binwalk scans files for embedded data, file signatures, and compressed sections.

When To Use It

  • inspect suspicious files for appended or embedded content
  • analyze firmware images and archives
  • look for hidden files inside images or binaries
  • carve out embedded files for follow-up analysis

Basic Usage

Inspect a file without extracting anything:

binwalk myFile

Extract discovered content into a new folder:

binwalk -e myFile

Extract recursively when embedded files contain more embedded content:

binwalk -Me myFile
  • extracted content is written to a new directory next to the original file
  • after extraction, review the output with tree, ls -R, file, strings, etc

Limitations

  • short signatures can create false positives
  • extraction may fail on malformed or partially corrupted data
  • binwalk is a starting point, not proof that a finding is meaningful

when presented with just a file, try binwalk first to see if it finds anything...
binwalk myFile - will just look inside without extracting

binwalk -eM myFIle

  • it will extract files to an 'extractions', and will list any extractions in a folder or file named by the address where it extracted it from

foremost

foremost carves files out of raw data by looking for known file headers and footers.

When To Use It

  • recover files from disk images or raw data
  • carve common file types out of suspicious files
  • follow up when binwalk extraction is incomplete
  • extract embedded files when you suspect hidden content

Basic Usage

Carve supported file types from a file:

foremost myFile

Choose an output directory:

foremost -i myFile -o output_dir

Carve only a specific file type, such as png:

foremost -t png -i myFile -o output_dir

Common Notes

  • -i selects the input file
  • -o selects the output directory
  • -t limits carving to specific file types
  • foremost usually creates an audit report along with carved files

Limitations

  • carving depends on recognizable headers and footers
  • fragmented or partially overwritten files may extract badly or incompletely
  • recovered files still need validation with tools like file, xxd, or manual review

Inspecting Memory dumps

  • Volatility
  • Windbg on Windows
  • look for running processes, commands that were run, environment variables, etc

Inspecting Disk images

Linux

  • the sleuth kit on linux
  • Autopsy browser UI on linux

Windows

  • FTK Imager

  • Autopsy

  • Event Viewer for inspecting logs

  • look for deleted files, users, etc.