Can you recover deleted but running exes on live OS X? Linux example of it: pastebin.com/LC3dj152 CC: @iamevltwin @osxreverser #DFIR
1
8
23
@iamevltwin @attrc @osxreverser "lsof +L1" to show unlinked open file CNID, then icat to recover?
1
@hal_pomeranz I will try that if I can figure out why TSK won’t compile. That didn’t work on Linux though
1
Replying to @attrc
@attrc Just tested it on my Yosemite box and it worked fine. I've done it on Linux too-- though there you can just use /proc/<pid>/exe

Feb 8, 2015 · 6:23 PM UTC

2
2
@attrc Hadn't looked at the pastebin-- but, yes, I just tested recovering deleted binary from a deleted directory with lsof/icat/Yosemite
1
@hal_pomeranz ah nice. Can you pastebin istat on the file and it's directory ?
1
Replying to @hal_pomeranz
@hal_pomeranz you tested with deleting the directory of the file and not just the file itself ? See the pastebin