If you do any kind of post-mortems on volumes with lost data, or hacked systems, you might want to check out Sleuthkit. If you use Fedora Core (as I do), you might want to check out my SRPMS (source RPMs) for both sleuthkit and autopsy. (Due to the fact that …