±Your Account
Membership:
New Today: 4
New Yesterday: 10
Overall: 24370
Visitors: 59±Latest Articles
· Catching the ghost: how to discover ephemeral evidence with Live RAM analysis
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
±Follow Us
±Latest Jobs
Back to top
Skip to content
Skip to menu
Back to top
Back to main
Skip to menu
Question RE:Recovered folders & overwritten files in Encase6
Question RE:Recovered folders & overwritten files in Encase6
Posted: Thu Sep 13, 2012 12:46 pm
Hello,
In Encase after running the recover folders function I am locating traces of image files that are being reported as overwritten/deleted. I can’t view these files using Encase’s usual undelete function.
My question is whether there is anyway to recover and view these files, and also can these files be bookmarked?
Thank you all,
In Encase after running the recover folders function I am locating traces of image files that are being reported as overwritten/deleted. I can’t view these files using Encase’s usual undelete function.
My question is whether there is anyway to recover and view these files, and also can these files be bookmarked?
Thank you all,
-
mbriggs - Newbie
Re: Question RE:Recovered folders & overwritten files in Encase6
Posted: Fri Sep 14, 2012 8:12 am
As I understand it, the "recover folders" feature looks for $MFT records in unallocated. Given the re-use of clusters, frequently you find that the data has been over-written - hence the lack of a viewable image.
So what these "over-written" entries show is not a file, but a record of a file which once existed. I don't think EnCase lets you bookmark them - the best you can do is blue-check them and right-click "export" a list.
So what these "over-written" entries show is not a file, but a record of a file which once existed. I don't think EnCase lets you bookmark them - the best you can do is blue-check them and right-click "export" a list.
-

Chris_Ed - Senior Member
Re: Question RE:Recovered folders & overwritten files in Encase6
Posted: Fri Sep 14, 2012 8:43 am
So as far as best practices go. What is the best way to document the existence of these types of files once they are located if EnCase won't let you bookmark them so you can incorporate them into your report?
-
mbriggs - Newbie
Re: Question RE:Recovered folders & overwritten files in Encase6
Posted: Sat Sep 15, 2012 5:45 pm
Would highlighting the record of the file i.e 'PictureOfInterest.jpg' in the Text view, right clicking and bookmarking as text, then incorporate the physical sector, file offset and length in the comments box provide you with a suitable record for court purposes. The details of the bookmarks can then be exported in a rtf from EnCase. This way if another expert were to examine the same job, they would be able to input that data (from your comment box) and see the name of the file(s) in question exactly where you found them.
-

scuzz - Member
Re: Question RE:Recovered folders & overwritten files in Enc
Posted: Mon Sep 17, 2012 11:21 am
Blue check all of the files, right click and Export. This will let you export all the file system data that Encase knows about. (You have to check the properties you want exported.)
Save it as a .csv, open it in Excel for pretty formatting purposes and you can then just put it in your report later.
_________________
Larry E. Daniel DFCP, EnCE, BCE, ACE
Guardian Digital Forensics - Firm
Ex Forensis - Blog
Encase 101 - Blog
Digital Forensics for Legal Professionals - Book
Save it as a .csv, open it in Excel for pretty formatting purposes and you can then just put it in your report later.
_________________
Larry E. Daniel DFCP, EnCE, BCE, ACE
Guardian Digital Forensics - Firm
Ex Forensis - Blog
Encase 101 - Blog
Digital Forensics for Legal Professionals - Book
-

LarryDaniel - Senior Member
















