ZFS forensics (mapping sector # to file name)

cpghost cpghost at cordula.ws
Thu Jun 16 14:56:26 UTC 2016


Hello ZFS gurus/admins,

how do you map a sector # to a ZFS object? Or, more concretely:

Suppose I'm inspecting a disk /dev/ada0p4[.eli] that belongs to a
zpool, and there's something interesting in sector #123456. How do
I determine to which file, directory, etc... on which ZFS dataset
this sector belongs, or if this sector belongs to a deleted file
(unallocated sector), or to something that was there all along before
the disk got reformatted to ZFS?

Any ideas? Forensics tools?

Thanks,

-cpghost.

-- 
Cordula's Web. http://www.cordula.ws/


More information about the freebsd-questions mailing list