August 2017
Intermediate to advanced
336 pages
11h 39m
English
It is common for people to delete files from their computers. Even criminals who are not very technically savvy think that deleting a file will keep authorities from discovering it. So you should expect that evidence will frequently be deleted from computers you examine. For this reason, one of the most fundamental tasks a forensic examiner will conduct is to retrieve deleted data.
This chapter does not delve into the specifics of the three major operating systems— Windows, Linux, and Macintosh. Instead, the focus is simply on recovering files from them. However, those operating system issues most closely related to deletion of files are discussed.
Hard drives store data as a sector. For many ...
Read now
Unlock full access