Skip to content

Digital Forensics

Digital forensics is the work of finding, preserving and examining evidence on computers, storage media and networks. These notes cover the practical side: where artefacts live, how data can be recovered, and how the tools used to collect and analyse it work. The posts in this category are listed below.

Cipher (Anti-forensics)

Something I came across recently in an incident response engagement was the potential use of "Cipher.exe". Let's take a look at how it works. The testing site is on an exFAT USB but in-depth analysis regarding the exFAT process of deleting files etc will not be discussed today but more so focussed on what Cipher.exe does to the file instead.

File Carving

File carving refers to a process used in Digital Forensics to recover data from a file system which has typically been deleted. File carving can be automated using software or done so manually. The sign of a good Digital Forensics practitioner is the ability to do this manually or at the minimum understand how this process is carried out when using forensic programs that can do it for you.