Undeleting Data
It is common for people to delete files from their computers. This does not necessarily mean they have nefarious intent; they may just be deleting files that are no longer needed. However, deleting files can also be a means of attempting to hide evidence. Even criminals who are not particularly technically skilled think that deleting a file will keep authorities from discovering it. Therefore, you should expect that evidence will frequently be deleted from computers you examine. For this reason, one of the most fundamental tasks a forensic examiner will perform is retrieving deleted data.
This chapter does not dive into the specifics of the three major operating systems—Windows, Linux, and macOS. Those details will be covered ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access