31
Evidence Analysis Text Searches Slack Space Unallocated Space

Evidence Analysis Text Searches Slack Space Unallocated Space

Embed Size (px)

Citation preview

Page 1: Evidence Analysis Text Searches Slack Space Unallocated Space

Evidence Analysis

Text SearchesSlack Space

Unallocated Space

Page 2: Evidence Analysis Text Searches Slack Space Unallocated Space

Text Searches

Page 3: Evidence Analysis Text Searches Slack Space Unallocated Space

Select “Simultaneous Search”Search Menu

Page 4: Evidence Analysis Text Searches Slack Space Unallocated Space

Talk to Your DAChoose pertinent Words for your

Investigation

Important for locating context

Page 5: Evidence Analysis Text Searches Slack Space Unallocated Space

Positive Reinforcement

Page 6: Evidence Analysis Text Searches Slack Space Unallocated Space

Select an EntryDrive displays that entry

Page 7: Evidence Analysis Text Searches Slack Space Unallocated Space

Using Position Manager

Page 8: Evidence Analysis Text Searches Slack Space Unallocated Space

Key Word Search

● Displays context of the key word● Go through every hit● What can you discern about the case?● Is it relevant to your case?

Page 9: Evidence Analysis Text Searches Slack Space Unallocated Space

Slack SpaceFree Space

What is lurking in the background

Page 10: Evidence Analysis Text Searches Slack Space Unallocated Space

Windows – Drives

● In Windows drives are specified by a letter followed by a colon.

● C:, D:, etc.

● Each drive is either a partition or an actual hard drive.

● Often referred to as logical drives.

Page 11: Evidence Analysis Text Searches Slack Space Unallocated Space

Files

● A File is data that is related, as such it is a logical grouping of data.

● Files are allocated storage space on a drive when it is created.

● As a file is used it is allocated more space as needed.

● File names usually have a first name that is descriptive of its contents.

● And a second name, the file extension, that indicates the type of file, such as .txt, .pdf, .exe, etc.

Page 12: Evidence Analysis Text Searches Slack Space Unallocated Space

Disk Storage Review

● Data is stored on disks one entire sector at a time

– A sector is usually 512 bytes

– If you use only one byte, the system still provides the other 511 bytes for you

– A sector is the minimum size read from, or written to, a disk

– A sector is the minimum I/O unit

Page 13: Evidence Analysis Text Searches Slack Space Unallocated Space

Clusters

● Space is allocated to a file one cluster at a time

– A cluster is a fixed number of sectors● Must be a power of 2 (1,2,4,8, ... 64)

– Unused sectors retain the data that was on them prior to allocation

– A cluster is the minimum file allocation unit

Page 14: Evidence Analysis Text Searches Slack Space Unallocated Space

Clusters

Sector 1

Sector 2

Sector 3

Sector 4

Cluster 1

Sector 1

Sector 2

Sector 3

Sector 4

Cluster 2

Page 15: Evidence Analysis Text Searches Slack Space Unallocated Space

File Data

Sector 1

Sector 2

Sector 3

Sector 4

Cluster 1

Sector 1

Sector 2

Sector 3

Sector 4

Cluster 2

Page 16: Evidence Analysis Text Searches Slack Space Unallocated Space

Slack Space

● Slack is the space allocated to a file, but unused

– Space at the end of a sector that remains unused by the file

– Sectors allocated to the file that the file hasn’t yet used

● Slack space often contains useful evidence

– Unused bytes in an allocated sector are less useful

– Unused sectors in an allocated cluster retain their original contents and are very useful

● Current operating systems write 0’s in the slack space per sector, often leaving the residual data in the unused sectors in the allocated cluster.

Page 17: Evidence Analysis Text Searches Slack Space Unallocated Space

File Data

Sector 1

Sector 2

Sector 3

Sector 4

Cluster 1

Sector 1

Sector 2

Sector 3

Sector 4

Cluster 2

Slack Space

Slack Space

Page 18: Evidence Analysis Text Searches Slack Space Unallocated Space

Unallocated Clusters

● Many clusters on a modern hard drive are unallocated

● Some have never contain data

● Unallocated clusters may have been allocated earlier though and since been deleted

– These clusters retain their data until they are reallocated to a new file

– Deleted files are still recoverable!

Page 19: Evidence Analysis Text Searches Slack Space Unallocated Space

Deleting a FAT FileDeleting C:taxes.txt

• Find the FAT, and Data areas

• Locate taxes.txt in the Directory for C:; determine its starting cluster

• Go to the FAT

• Set FAT entries for taxes.txt cluster to 0• Therefore not allocated• Follow the links

• Change filename to axes.txt in C: directory

– First character becomes 0xE5

Page 20: Evidence Analysis Text Searches Slack Space Unallocated Space

Unallocated Space

● After deleting a file the previously allocated clusters become unallocated.

● They ready to be allocated to some other file.

● They have not been touched.● They still contain the data from the

original file.● You can recover the data so long it

hasn’t been written over by a new file.

Page 21: Evidence Analysis Text Searches Slack Space Unallocated Space

WinHex to the Rescue

● Presents the file system● Lets you look at the individual files● Shows files that have been deleted● Attempts to recover deleted files● Gathers slack space

Page 22: Evidence Analysis Text Searches Slack Space Unallocated Space

Go get the Slack

Page 23: Evidence Analysis Text Searches Slack Space Unallocated Space

Save It

Page 24: Evidence Analysis Text Searches Slack Space Unallocated Space

View ItNot terribly interesting

Page 25: Evidence Analysis Text Searches Slack Space Unallocated Space

Go Get Free Space

Save it in your case folder

Page 26: Evidence Analysis Text Searches Slack Space Unallocated Space

Viewing Free Space

Page 27: Evidence Analysis Text Searches Slack Space Unallocated Space

Text Search

● “Simultaneous Search”● First you must delete all positions from

the first search● Then search

Page 28: Evidence Analysis Text Searches Slack Space Unallocated Space

Deleting Previous Searches

Page 29: Evidence Analysis Text Searches Slack Space Unallocated Space

List of Hits

Page 30: Evidence Analysis Text Searches Slack Space Unallocated Space

Select Delete

Delete

Page 31: Evidence Analysis Text Searches Slack Space Unallocated Space

Lab Assignment

● Select keywords and search for them.

● Gather slack space and comment

● Gather free space and comment

● Search free space for keywords

● Highlight some of the keyword hits in free space

● Be sure you comment on the relevance of your discovered evidence on the charges