Recycle Bin
Let us start with an older Recycle Bin, the one found in Windows 2000 and Windows XP. The reason to cover older versions is that you may very well encounter older systems in digital forensics.
The default Recycle Bin configuration for a Windows computer is to move deleted files to a folder named \Recycler\%SID%\, where %SID% is the SID (Security Identifier) of the currently logged on user. Every user on the system will have such a directory created the first time that the Recycle Bin is used. As well, each user will have a hidden file called INFO2 that is created the first time the Recycle Bin is used—its purpose is to keep track of the location of a deleted file or folder as well as file size and deletion time. This makes it possible ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access