Home > Computer Forensic > Where Should Computer Forensics Begin?

Where Should Computer Forensics Begin?

December 3rd, 2008

Analysis Areas
–Email
–Temp Files
–Recycle Bin
–Info File Fragments
–Recent Link Files
–Spool (printed) files
–Internet History (index.dat)
–Registry
–Unallocated Space-free space on the hard drive
–File Slack-free space between the end of the logical file and the end of physical file (cluster)
–RAM Slack-free space between the end of the logical file and the end of the containing sector
•Sector-the smallest group that can be accessed on the disk. A group of disk sectors as assigned by the operating system are known as clusters

Comments are closed.