So for those that dont know volatility is a forensics tool for investigating data from memory. It can be found here:

Unfortunately BT5 was only on version 1.3 so I decided to update it to v2.0, the latest on the volatility website.

Here’s the quick code to update to version 2.0 🙂 Enjoy!

#!/bin/bash apt-get -y install cmake cd /root/ wget tar zxvf libforensic1394-0.2.tar.gz cd libforensic1394-0.2/ cmake -G"Unix…

This allows you to mount an iso file in a linux directory

1mount -o loop file.iso /mnt/cdrom

This will verbosely sync the 2 directories locally

1rsync --delete --progress --sparse -va /dir/of/source/ /dir/of/destination/

And to do the same thing over SSH:

1rsync --sparse --progress -avc -e ssh /dir/of/destination/