Elena Pakhomova, Co-Founder, ReclaiMe

Elena, you co-founded ReclaiMe; could you tell us a bit about what made you decide to start the company?

Data recovery is our family business. Initially my sister and her husband were involved in data recovery. Then I became a part of the team. If someone long ago had said that I would do this, I would probably have laughed. However, at this point I associate myself only with this business. No wonder they say that life is unpredictable.

What does your day to day role entail? Which aspects do you find the most challenging, and the most rewarding?

Every working day starts with the support. Basically it includes some routine questions, like differences in licenses, software activation, and so on. However, sometimes we face the complex cases that cannot be resolved quickly.Typically, data recovery technicians bring us such recovery cases and we are very grateful to them, because it allows us to improve algorithms in our tools, so that our tools could work where others cannot. Another kind of day-to-day work is developing new data recovery algorithms. Frankly speaking, I cannot remember even a single day when we did not think about something new. Microsoft has released ReFS and Storage Spaces and we do recover data from them. NETGEAR started to use BTRFS instead of EXT and now we are able to extract data from it too. Every week something new happens and we have to adapt to keep up.

Briefly tell us about the software ReclaiMe creates – what specific challenges faced by digital forensics professionals are you looking to address?


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

We all know data recovery and computer forensics are closely related to each other; that’s why often our customers are police departments and e-discovery companies. Computer forensics software aims to extract and analyze information from healthy, or slightly damaged filesystems. On the contrary, ReclaiMe software is designed to recover data even from severely damaged filesystems. More than that, at the moment data recovery from some filesystems and partitioning schemes is possible only with ReclaiMe.

Also I would like to mention our pride – RAID and NAS recovery and the fact that ReclaiMe software supports almost all common RAID types and operates with various NAS devices. The forensic toolkit as it is applied to the traditional storage, that is, to hard drives rather than to mobile phones, works best if the data deletion or other sort of destruction was not attempted. However, it is easy and quick to ruin the filesystem, after which data recovery software becomes your best choice because it is specifically designed to work with a ruined filesystem. While forensic software developers had their practice to sift through data, we had our practice to extract that data, and forensic software often stops short of what can really be recovered.

You've recently released ReclaiMe Pro, a data recovery toolkit. What exactly does it do, and what are the main features which set it apart from similar forensic tools?

The idea of creating ReclaiMe Pro arose when data recovery technicians came to ask us to implement some features in the end-user ReclaiMe, to give them the ability to do custom settings. However, this is completely contrary to the end-user expectations which can be described in the single sentence “No setting buttons”. So especially for experts we released ReclaiMe Pro, where they can customize everything they want. If we talk about the distinctive features we are very proud of built-in RAID analysis – content and entropy, using which you can get a lot of information about the RAID you need to recover data from. Throw in a good imager, close to the best one can achieve in software.

What current trends are of interest to you in digital forensics, and what new challenges do you envisage in the future?

As for the difficulties, in my opinion, these are the growing volume of stored data and the increasing complexity of methods of storing data. Recently, we have worked with the 250 GB devices and were quite pleased. Now we can go to the electronic store and buy a 6 TB disk. Since the speed has not grown in proportion, the analysis time has increased. This is also true for the methods of storing data – we know NTFS from A to Z, as well as all other data recovery vendors. However, in recent years new filesystems come on the market. For example, just a couple of years ago BTRFS was only for geeks, but today it can be found in devices sold by thousands of pieces on the mass-market.

Unfortunately, I think that the life of data recovery and forensic experts will get harder and harder, but at the same time, we will not get bored.

What does the future hold for ReclaiMe specifically? What can we expect to see over the next few years?

I can assure you that ReclaiMe does not stand still, we are constantly developing something new. For example, we have just completed the implementation of algorithms for BTRFS recovery in our software. We promise that ReclaiMe will always keep up with the times. When they invent new filesystems, new partitioning schemes, we will still learn to recover data from them.

Finally, what do you do to relax when you're not working?

I have a very big family and we often get together for dinner or to go somewhere, like cinema or theater. Also, we love to spend holidays together in hot countries – the more the merrier.

And of course, sometimes I want to be alone, for example, in the company of a good book.

Leave a Comment

Latest Videos

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools. 

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

In this episode of the Forensic Focus podcast, Si and Desi explore how artificial intelligence is being leveraged to uncover crucial evidence in investigations involving child sexual abuse material (CSAM) and examine the importance of exercising caution when implementing these tools.

They also discuss a recent murder case in which cyber experts played a vital role in securing a conviction, and explore the unique challenges associated with using digital evidence as an alibi.

Show Notes:

A Practitioner Survey Exploring the Value of Forensic Tools, AI, Filtering, & Safer Presentation for Investigating Child Sexual Abuse Material (CSAM) - https://dfrws.org/wp-content/uploads/2019/06/2019_USA_paper-a_practitioner_survey_exploring_the_value_of_forensic_tools_ai_filtering_safer_presentation_for_investigating_child_sexual_abuse_material_csam.pdf

Man charged with NI murder ‘faked live stream to provide alibi’ (The Guardian) - https://www.theguardian.com/uk-news/2023/feb/02/man-charged-with-ni-faked-live-stream-to-provide-alibi

A YouTuber accused of murder faked a 6-hour livestream to produce an alibi (Sportskeeda) - https://www.sportskeeda.com/esports/news-a-youtuber-accused-murder-faked-6-hour-livestream-produce-alibi

European Interdisciplinary Cybersecurity Conference (EICC) 2023 - https://www.forensicfocus.com/event/european-interdisciplinary-cybersecurity-conference-eicc-2023/#more-493234

YouTuber reportedly faked GTA livestream to have an alibi while he committed murder (Dexerto) - https://www.dexerto.com/entertainment/youtuber-reportedly-faked-gta-livestream-to-have-an-alibi-while-he-committed-murder-2052974/

Forensic Europe Expo - https://www.forensicfocus.com/event/forensic-europe-expo/#more-493225

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_7QiFTiuY7Vw

AI In CSAM Investigations And The Role Of Digital Evidence In Criminal Cases

Forensic Focus 22nd March 2023 12:44 pm

Throughout the past few years, the way employees communicate with each other has changed forever.<br /><br />69% of employees note that the number of business applications they use at work has increased during the pandemic.<br /><br />Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.<br /><br />Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.<br /><br />Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.<br /><br />With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.<br /><br />Join Monica Harris, Product Business Manager, as she showcases how investigators can:<br /><br />- Manage multiple cloud collections through a web interface<br />- Cull data prior to collection to save time and money by gaining these valuable insights of the data available<br />- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box<br />- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee<br />- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

Throughout the past few years, the way employees communicate with each other has changed forever.

69% of employees note that the number of business applications they use at work has increased during the pandemic.

Desk phones, LAN lines and even VOIP have become technologies of the past workplace environment as employees turn to cloud applications on their computers and phones to collaborate with each other in today’s workplace environment.

Whether it’s conversations in Teams, file uploads in Slack chats, or confidential documents stored in Office 365, the amount of data stored and where it is stored, is growing quicker than IT and systems administrators can keep up with.

Corporate investigators and eDiscovery professionals need to seamlessly collect relevant data from cloud sources and accelerate the time to investigative and discovery review.

With the latest in Cellebrite’s remote collection suite of capabilities, investigators and legal professionals can benefit from secure collection with targeted capabilities for the most used workplace applications.

Join Monica Harris, Product Business Manager, as she showcases how investigators can:

- Manage multiple cloud collections through a web interface
- Cull data prior to collection to save time and money by gaining these valuable insights of the data available
- Collect data from the fastest growing cloud collaboration applications like Office365, Google Workspace, Slack and Box
- Login to a single source for workplace app collection without logging into every app and pulling data from multiple sources for every employee
- Utilize a single unified collection workflow for computer, mobile and workplace cloud applications without the need to purchase multiple tools for different types of collections – a solution unique to Cellebrite’s enterprise solution capabilities

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_g6nTjfEMnsA

Tips And Tricks Data Collection For Cloud Workplace Applications

Forensic Focus 20th March 2023 12:00 pm

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles

Share to...