USB drive forensic:...
 
Notifications
Clear all

USB drive forensic: looking for trace of classified document

6 Posts
5 Users
0 Reactions
612 Views
(@francis87)
Active Member
Joined: 17 years ago
Posts: 18
Topic starter  

first of all, I really can't think of any good title for this posting. Bear with me .=)

My client want me to trace whether a classified document was tranferred from the hard disk onto a USB drive. But the very problem that I have now is I only have the hard disk. No USB drive was presented to me.

My question is there any way to find out what files were copied onto a USB drive with only the hard disk?


   
Quote
(@dficsi)
Reputable Member
Joined: 19 years ago
Posts: 283
 

Is it an XP or Vista (or not of the above) machine?

If its XP this article may help you

http//sansforensics.wordpress.com/2008/10/31/shellbags-registry-forensics/

Used this on cases before and found a lot of useful information.


   
ReplyQuote
(@tootypegs)
Trusted Member
Joined: 18 years ago
Posts: 80
 

look at the recent link files and examine them to retrieve the volume serial no for lnnks that point to documents that are in question (if these lnks exist). It wont prove they were copied but maybe they got opened from the pen drive?


   
ReplyQuote
(@mscotgrove)
Prominent Member
Joined: 17 years ago
Posts: 940
 

Will the $logfile contain an entry to say a file has been accessed?

In theory, the MFT should be updated, so I might expect a log entry. It won't say why, but should say when.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

My client want me to trace whether a classified document was tranferred from the hard disk onto a USB drive. But the very problem that I have now is I only have the hard disk. No USB drive was presented to me.

My question is there any way to find out what files were copied onto a USB drive with only the hard disk?

I think we've covered this here a number of times before, as well as here
http//windowsir.blogspot.com/2008/07/copying-files.html

The fact of the matter is that under the conditions you've mentioned, there are really no means by which you can provide an accurate answer to your customer.

Yeah, shell bags are great…but they won't tell you which files someone copied from a system to a USB thumb drive.

Same with Windows shortcut/.lnk files…they'll tell you which files someone opened from a thumb drive (via Explorer, navigate to a thumb drive, double click a file, say a Word doc).

And yes, Registry analysis will show you the thumb drives that had been attached to the system.

However, there simply aren't any logs (or, by extension, analysis techniques) that will tell you which files were copied from the system to a thumb drive, under the conditions you've stated.


   
ReplyQuote
(@francis87)
Active Member
Joined: 17 years ago
Posts: 18
Topic starter  

thanks everyone for the post.

hmm……….. it seem that it's impossible to know exactly, or to prove exactly that a file was tranferred from the hard disk to the usb drive.


   
ReplyQuote
Share: