Missing file attrib...
 
Notifications
Clear all

Missing file attributes in the drive freespace area

5 Posts
3 Users
0 Reactions
365 Views
(@gapcop)
New Member
Joined: 17 years ago
Posts: 2
Topic starter  

I am doing a forensic exam on a suspect drive and all of the illegal images are showing they are located in the drivefreespace and under the areas of Created Date, Accessed Date, and Modified Date it just indicates N/A. Why is this? I need to prove that the illegal images were accessed during a certain time frame to connect them to the suspect, since it was not his computer, but only he had access to it during a particular time frame


   
Quote
 ddow
(@ddow)
Reputable Member
Joined: 21 years ago
Posts: 278
 

It'll help if you can provide that tools you're using and the file system of the drive. As to the access question, is this a stand alone system or on a domain?


   
ReplyQuote
(@gapcop)
New Member
Joined: 17 years ago
Posts: 2
Topic starter  

I am using FTK on an image of a hard drive, and the file system is NTFS


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

I am doing a forensic exam on a suspect drive and all of the illegal images are showing they are located in the drivefreespace and under the areas of Created Date, Accessed Date, and Modified Date it just indicates N/A. Why is this?

Because there is no entry in the MFT or associated INFO2 record that contains that information.

I need to prove that the illegal images were accessed during a certain time frame to connect them to the suspect, since it was not his computer, but only he had access to it during a particular time frame

Any link or thumbnail files that can point to this time frame?


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

And I guess I should add, have you searched for any INFO2 records that contain data that would suggest that the files were in the Recycle Bin during the time in question?


   
ReplyQuote
Share: