Text Searches Slack Space Unallocated Space

Slides:



Advertisements
Similar presentations
Intro to WinHex CSC 414.
Advertisements

The Windows File System and Windows Explorer To move around the file system and examine your files or get to one you want (say, to modify, delete or copy.
Computer Forensic Analysis By Aaron Cheeseman Excerpt from Investigating Computer-Related Crime By Peter Stephenson (2000) CRC Press LLC - Computer Crimes.
A batch file is a file that contains a number of DOS commands, each of which could be run individually from the command prompt. By putting them into a.
Operating Systems File Management.
Computing Fundamentals Module Lesson 5 — File Management with Windows Explorer Computer Literacy BASICS.
Computer Data Forensics Drive Slack and Format – Lab 2 Concept Joe Cleetus Concurrent Engineering Research Center, Lane Dept of Computer Science and Engineering,
SEMINAR ON FILE SLACK AND DISK SLACK
Computer Forensics BACS 371
1 X-Ways Security: Permanent Erasure Supervised By: Dr. Lo’ai Tawalbeh Prepared By :Murad M. Ali.
MODULE 4 File and Folder Management. Creating file and folder A computer file is a resource for storing information, which is available to a computer.
Lesson 3: File Management. 2 Learning Objectives After studying this lesson, you will be able to:  Browse files on the computer  Open files from a folder.
File System Analysis.
Digital Forensics Module 11 CS /26/2004Module 112 Outline of Module #11 Overview of Windows file systems Overview of ProDiscover Overview of UNIX.
MCT260-Operating Systems I Operating Systems I Navigating the File System.
X-Ways Trace Prepared By: Leen F. Arikat Supervisor: Dr. Lo’ai Tawalbeh.
Lecture 10: The FAT, VFAT, and NTFS Filesystems 6/17/2003 CSCE 590 Summer 2003.
Managing Your Files. Objectives Develop file management strategies Explore files and folders Create, name, copy, move, and delete folders Name, copy,
1 Friday, July 07, 2006 “Vision without action is a daydream, Action without a vision is a nightmare.” - Japanese Proverb.
Operating Systems File systems
COS/PSA 413 Day 15. Agenda Assignment 3 corrected –5 A’s, 4 B’s and 1 C Lab 5 corrected –4 A’s and 1 B Lab 6 corrected –A, 2 B’s, 1 C and 1 D Lab 7 write-up.
Data Recovery/Discovery Files Deleted Files Text Searches Slack Space Free Space Lab.
Computing Fundamentals Module Lesson 5 — File Management with Windows Explorer Computer Literacy BASICS.
Storage and NT File System INFO333 – Lecture Mariusz Nowostawski Noria Foukia.
FAT Structure. File Allocation Table (FAT) File Systems Used with all flavors of Windows Supported by all Windows and UNIX varieties Used in flash cards.
BACS 371 Computer Forensics
Computer Literacy BASICS: A Comprehensive Guide to IC 3, 5 th Edition Lesson 3 Windows File Management 1 Morrison / Wells / Ruffolo.
Rensselaer Polytechnic Institute CSCI-4210 – Operating Systems David Goldschmidt, Ph.D.
File Systems Long-term Information Storage Store large amounts of information Information must survive the termination of the process using it Multiple.
Bits, Bytes, Files, Hard Drives. Bits, Bytes, Letters and Words ● Bit – single piece of information ● Either a 0 or a 1 ● Byte – 8 bits of information.
4.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 4: Organizing a Disk for Data.
File Systems Dr John Cowell phones off (please). Q 1 Which of the following statements about NTFS is NOT true? a) NTFS uses 64 bit addressing. b) Supports.
Computing Fundamentals Module Lesson 10 — File Management with Windows Explorer Computer Literacy BASICS.
The Functions of Operating Systems Desktop PC Operating Systems.
XP New Perspectives on Windows 2000 Professional Windows 2000 Tutorial 2 1 Microsoft Windows 2000 Professional Tutorial 2 – Working With Files.
Lesson 12: Using the Recycle Bin deleting files or folders what the Recycle Bin is restoring files from the Recycle Bin emptying the Recycle Bin identifying.
File Storage Organization The majority of space on a device is reserved for the storage of files. When files are created and modified physical blocks are.
1 Lesson Three. 2 Opening a Document Inserting Text Deleting a Character Deleting a Word Deleting a Sentence Automatic Braille Advance.
DISK THEORY. Disk Theory n How information is stored on disk n How we can take advantage of that when bad things happen.
Computer Data Expert The following slides are from a presentation developed to support/explain a Data Forensics expert testimony. Click or hit spacebar.
Working with Disks Lesson 4. Skills Matrix Technology SkillObjective DomainObjective # Configuring Data Protection Configure data protection6.4 Using.
Unit 2—Using the Computer Lesson 9 Windows and File Management.
University of Pennsylvania 10/31/00CSE 3801 Windows File System - FAT originally invented as a method for storing data on floppy disks. later used by MS-DOS.
FAT File Allocation Table
© Janice Regan, CMPT 300, May CMPT 300 Introduction to Operating Systems File systems.
Landscaper 101. Time Code AMC AMCNET HELP!!! Where do you go for help? –Upper right corner has a ? for the online help –This presentation.
Computer Literacy BASICS: A Comprehensive Guide to IC 3, 5 th Edition Lesson 3 Windows File Management 1 Morrison / Wells / Ruffolo.
XP New Perspectives on Microsoft Windows XP Tutorial 2 1 Microsoft Windows XP Working with Files Tutorial 2.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #8 File Systems September 22, 2008.
Chapter 8 File Systems FAT 12/16/32. Defragmentation Defrag a hard drive – Control Panel  System and Security  Administration tools  Defrag hard drive.
FILE MANAGEMENT Computer Technology Timpview High School.
Senior 3 Computer Studies
Windows 7 and file management
Microsoft Windows 7 - Illustrated
Computer Literacy BASICS
Understanding File Management
Windows XP File Systems
Introduction to Computers
Introduction to Computers
Understanding File Management
File Management.
File Managements.
Forensic Concept of Data
Optimizing Disks CGS2564.
COMP1321 Digital Infrastructures
Modern PC operating systems
Disk Structure Analysis
File System Implementation
Partitioning & Formatting
FAT File System.
Presentation transcript:

Text Searches Slack Space Unallocated Space Evidence Analysis Text Searches Slack Space Unallocated Space

Text Searches

Select “Simultaneous Search” Search Menu

Talk to Your DA Choose pertinent Words for your Investigation Important for locating context

Positive Reinforcement

Select an Entry Drive displays that entry

Using Position Manager

Key Word Search Displays context of the key word Go through every hit What can you discern about the case? Is it relevant to your case?

What is lurking in the background Slack Space Free Space What is lurking in the background

Windows – Drives In Windows drives are specified by a letter followed by a colon. C:, D:, etc. Each drive is either a partition or an actual hard drive. Often referred to as logical drives.

Files A File is data that is related, as such it is a logical grouping of data. Files are allocated storage space on a drive when it is created. As a file is used it is allocated more space as needed. File names usually have a first name that is descriptive of its contents. And a second name, the file extension, that indicates the type of file, such as .txt, .pdf, .exe, etc.

Disk Storage Review Data is stored on disks one entire sector at a time A sector is usually 512 bytes If you use only one byte, the system still provides the other 511 bytes for you A sector is the minimum size read from, or written to, a disk A sector is the minimum I/O unit

Clusters Space is allocated to a file one cluster at a time A cluster is a fixed number of sectors Must be a power of 2 (1,2,4,8, ... 64) Unused sectors retain the data that was on them prior to allocation A cluster is the minimum file allocation unit

Clusters Cluster 1 Cluster 2 Sector 1 Sector 1 Sector 2 Sector 2

File Data Cluster 1 Cluster 2 Sector 1 Sector 1 Sector 2 Sector 2

Slack Space Slack is the space allocated to a file, but unused Space at the end of a sector that remains unused by the file Sectors allocated to the file that the file hasn’t yet used Slack space often contains useful evidence Unused bytes in an allocated sector are less useful Unused sectors in an allocated cluster retain their original contents and are very useful Current operating systems write 0’s in the slack space per sector, often leaving the residual data in the unused sectors in the allocated cluster.

File Data Slack Space Cluster 1 Cluster 2 Sector 1 Sector 1 Sector 2

Unallocated Clusters Many clusters on a modern hard drive are unallocated Some have never contain data Unallocated clusters may have been allocated earlier though and since been deleted These clusters retain their data until they are reallocated to a new file Deleted files are still recoverable!

Deleting a FAT File Deleting C:taxes.txt Find the FAT, and Data areas Locate taxes.txt in the Directory for C:; determine its starting cluster Go to the FAT Set FAT entries for taxes.txt cluster to 0 Therefore not allocated Follow the links Change filename to axes.txt in C: directory First character becomes 0xE5

Unallocated Space After deleting a file the previously allocated clusters become unallocated. They ready to be allocated to some other file. They have not been touched. They still contain the data from the original file. You can recover the data so long it hasn’t been written over by a new file.

WinHex to the Rescue Presents the file system Lets you look at the individual files Shows files that have been deleted Attempts to recover deleted files Gathers slack space

Go get the Slack

Save It

View It Not terribly interesting

Go Get Free Space Save it in your case folder

Viewing Free Space

Text Search “Simultaneous Search” First you must delete all positions from the first search Then search

Deleting Previous Searches

List of Hits

Select Delete Delete

Lab Assignment Select keywords and search for them. Gather slack space and comment Gather free space and comment Search free space for keywords Highlight some of the keyword hits in free space Be sure you comment on the relevance of your discovered evidence on the charges