±Forensic Focus Partners
New Today: 0
New Yesterday: 6
· A guide to RegRipper and the art of timeline building
· Recovering Evidence from SSD Drives in 2014: Understanding TRIM, Garbage Collection and Exclusions
· FT Cyber Security Summit 2014 – Recap
· Why Offender Profiling is Changing Thanks to Mobile Forensics and Increasingly ‘Social’ Criminal Activity
· Understanding Cyber Bullying – Notes for Digital Forensics Examiners
· Investigating the Dark Web – The Challenges of Online Anonymity for Digital Forensics Examiners
· The Complete Workflow of Forensic Image and Video Analysis
· Browser Anti Forensics
· Coming apart at the SIEMs …
±Follow Forensic Focus
Encase naming confusing for overwritten and overwriting file
Do you know why Encase calls a file overwritten while it actually shows the overwriting one? It actually shows you something different from what it says it does.
If it shows me an overwriting file, it should call it the overwriting file, not the overwritten file.
I know that some forensic examiners and newbies may be deceived by this. Would it not be better, if it called the area -rather than the file- overwritten and show the current file as overwriting?
- Senior Member
- yunusDo you know why Encase calls a file overwritten while it actually shows the overwriting one? It actually shows you something different from what it says it does.
What you are seeing is a MFT record of a deleted file where the MFT record has not be overwritten but the file has. EnCase (in fact, no program of which I am aware), can display the contents of a file that has been overwritten. What EnCase is showing you is that the file pointer still exists though the file does not.
If you look at the very bottom of the EnCase Window (what they call the Navigation data or GPS), what is displayed is the path to actual file that now occupies the blocks occupied by the deleted file.
- Senior Member