Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
COMPUTER FORENSIC
DATA RECOVERY TECHNIQUES
AND SOLUTIONS WORKSHOP
COMPUTER FORENSIC
DATA RECOVERY
TECHNIQUES AND
SOLUTIONS WORKSHOP
Objectives:
HDDs.
• To examine the principles and methods
COMPUTER FORENSIC
• File Deletion
• Crash Windows operating system corrupt.
DATA RECOVERY TECHNIQUES
AND SOLUTIONS WORKSHOP
hardware/software
• Virus /malware infection.
Logical Failures
Retrieve Data
Damage or corruption
Restore Data
to the file system is
The retrieved data is
diagnosed and repaired
then copied to new
to permit access to the
media (for example
individual files. Individual
a USB drive) and
files are checked
returned to the client
for corruption and
repaired if necessary.
Basic File system
explanation
File System
machines by using Group Policy
• A file system is a means to organize data
expected to be retained after a program
Deploy a MSI on multiple
compressed.
• NTFS is a recoverable file system, meaning it has the
ability to undo or redo operations that failed due to such
problems as system failure or power loss.
• Disk quotas: Administrators can limit the amount of disk
space users can consume on a per-volume basis.
• Encryption: The NTFS 5.0 file system can automatically
encrypt and decrypt file data as it is read and written to
the disk.
FAT32
machines by using Group Policy
• FAT32 is the file system used in some older versions of
Microsoft Windows. You can also install the FAT32 files
Deploy a MSI on multiple
+ Sets an attribute.
- Clears an attribute.
R Read-only file attribute.
A Archive file attribute.
S System file attribute.
H Hidden file attribute.
I Not content indexed file attribute.
[drive:][path][filename]
Specifies a file or files for attrib to process.
/S Processes matching files in the current folder
and all subfolders.
/D Processes folders as well.
/L Work on the attributes of the Symbolic Link
versus
the target of the Symbolic Link
LAB 1
• CMD
• Type attrib /?
• View attribute via explorer
LAB 2
• How to view a computer file
extension
Viewing the file extension of a single file
• When you delete a file, the complete path and file name
is stored in a hidden file called Info or Info2 in the
Recycled folder. The deleted file is renamed, using the
following syntax:
• D<original drive letter of file><#>.<original extension>
Bin is Located?
LAB 5
• Recycle Bin
• Delete key
• Shift + Delete
• Delete Fails
• Delete Folder
• Delete Words /Excel / PDF / JPG
LAB
• Install Recuva
Where the Windows Recycle RECUVA