Installing HDFS for Forensics Research

It sure has been a long time since I last wrote anything here, so I remembered there was a blog that is either dead or is about to die :)

Anyway, just wanted to say “hi” to everyone out there and let them know the blog is not dead, I will be sharing some of the work I have been doing, as soon as I can. For now, just wanted to share a couple of documents for those interested in working on HDFS.

In the past year (maybe more!), I worked with two of my friends (Mariam and Dr. Ghazi) back in Jordan on HDFS Forensics. One of the research was already published and could be found here. While the other is still not published yet, but eventually it will be. When that happens, I will also release the simple file carver I wrote to carve core HDFS files (more later).

Setting up HDFS is not that complicated, but just in case some feel it is, the documents you find here covers a setup using a latest Ubuntu 18.04 build. Feel free to copy whatever you find in my repository. If you happen to have issues, then just let me know, I will be uploading my setup as OVA files. Therefore, all you will need to do is import them into your VMWare environment (or whatever hypervisor you use).

That’s all for now!