Upload
abra-weaver
View
29
Download
1
Tags:
Embed Size (px)
DESCRIPTION
Real Forensics. The hard way. Data Recovery. What data/evidence can you retrieve from a hard drive. Usually dd is good enough Sometimes real help is needed. Real Help. Hard Drive recovered from Columbia Shuttle accident February 1, 2003 400 Mbyte - PowerPoint PPT Presentation
Citation preview
Data Recovery
• What data/evidence can you retrieve from a hard drive.
• Usually dd is good enough
• Sometimes real help is needed
Real Help
• Hard Drive recovered from Columbia Shuttle accident
• February 1, 2003
• 400 Mbyte http://www.sciam.com/article.cfm?id=hard-drive-recovered-from-columbia
• 99% of the data was recovered from a Xenon shear thinning experiment
Ontrack Data Recovery
• Probably:– Remove the platters and cleaned them.
– Rebuilt the Spindle assembly
– Mounted in a new case
– Exercised in a clean room
Best Known
• HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
• A MRU list for about every application
• Used by the app to list your last accessed docs from that app.
Search AssistantSubkeys are for different search approaches:
5001 – Internet Search Assistant5603 – XP file search5604 – “word or phrase in a file”
System Restore Points
• Restore the system to a previous state
• Restore Points built in the background– Trigged by installation of apps/drivers
(unsigned)– Done once a day by default
What gets restored
• Registry
• Local profiles
• COM+ database
• WFP DLL cache
• WMI database
• IIS database
What doesn’t.
• DRM
• WPA settings
• SAM hive
• User-created data stored in the user profile
• Contents of redirected folders
System Restore ConfigurationRestore Point updates in seconds = 1 day
Retention of Restore Points in seconds