Question

This is a question about digital forensics and how it relates to Windows file systems, specifically...

This is a question about digital forensics and how it relates to Windows file systems, specifically FAT and NTFS. How might knowledge about these two file structures (NTFS and FAT) be useful to a digital forensics examiner? How would it help them with their process? Please explain in detail. Thank you!

Homework Answers

Answer #1

Yes, NTFS and FAT are very useful now a days and in future,especially in the forensics arena. With constantly changing technology, operating systems and file systems will be constantly updating to support the technology. As a forensic examiner it is important to keep up with and understand these new file systems. The next step is a look into ReFS, and how it compares to past file system forensic analysis. Also, since ReFS will be introduced with the new Windows 8 server, an analysis on data extracted from the OS could be looked at, with respect to the control and organization of the resilient file system.

Both systems offer forensic evidence that is significant and mandatory in an investigation.Knowing how these file systems work and the layout of key structures, storage mechanisms, associated metadata, and file system characteristics is essential to being able to forensically investigate a computer or other device. The New Technology File System (NTFS) and File Allocation Table (FAT32) are two key file systems that will be compared and contrasted, since both are still actively used and encountered often.

Now that we are aware of all the characteristics of both file allocation systems,reasoning behind forensic choices. In my capacity as a forensic computer investigator, one of my functions is to make perfect images of suspect hard drives with no data pollution. We have many ways of performing this task but the preferred method is to use the ENCASE tools. ENCASE can easily be used in a Windows or DOS environment. ENCASE can be used for single hard disks or servers. Usually, the drives we have to image are as large as the largest hard disk on the market. To access the suspect’s drive we plug in the FASTBLOCthrough our laptop (PCMCIA) and send the raw data to an external hard disk by using the ENCASE program in a Windows 2000 environment on our forensic laptop. While using this procedure, the evidence drive (the one containing the image) can be formatted in either FAT 32 or NTFS, since Windows 2000 recognize both. That process is mainly how we proceed with our forensic imaging of IDE drives.

In the forensic world we know that our expertise will be challenged repeatedly by the judicial system and we have to be consistent with all the procedures that we use and be able to explain the unexplainable. Basically we need to defend our work and the results attached to it. In our case the problem experienced by the investigators with the different file allocation table was reviewed and the process of wiping, formatting and partitioning was modified to be uniform and problem free when on site. As of now every investigator has to include in their tool box at least one hard disk of both format (FAT 32 and NTFS). These hard drives will be wiped, formatted and partitioned the same way all the time. We use a wiping utility in accordance with the Department of National Defense standard 5220.22-M (DND) meaning three passes are performed on every disk, the disks are formatted then partitioned in FAT 32 (irrelevant of the disk sizes) or NTFS. It was a learning experience that fortunately did not affect the end result of our investigation but made our inquiring minds work overtime to figure out the problem.

In order to facilitate our work in the future, we would need to either use FAT 32 hard disks or switch our Native DOS program to NTFS DOS.

Know the answer?
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for?
Ask your own homework help question
Similar Questions
Question 2 Vehicles are fast becoming another important source of digital evidence in a criminal investigation....
Question 2 Vehicles are fast becoming another important source of digital evidence in a criminal investigation. Traditionally, when a vehicle is involved in a crime scene (e.g. drink driving) or a terrorist attack, the investigators focus on the acquisition of DNA, fingerprints and other identifying materials that are usually non-digital in nature. However, modern-day cars, particularly smart or driverless cars, store a wealth of digital information. Vehicle forensics, therefore, is a valuable source of digital forensics data. Assume that you...
Question 1 (25 marks / Financial Systems) (a) What are the five functions of a financial...
Question 1 (25 marks / Financial Systems) (a) What are the five functions of a financial market? (b) Usually, basic financial markets have five basic functions in a capitalistic economy: For each of the functions cited below, explain how financial markets perform each function in detail. They make it possible for corporations and governmental units to raise capital. They help to allocate capital toward productive uses. They provide an opportunity for people to increase their savings by investing in them....
QUESTION 44 The key phrase that describes the concept of quantum computing is A. Exponentially scalable...
QUESTION 44 The key phrase that describes the concept of quantum computing is A. Exponentially scalable and highly parallel computing B. Able to accommodate massive quantities of data C. Able to connect to an increased number of devices D. Accommodates a quantum leap in the number of memory cards in a device 2 points    QUESTION 45 Revenue models for most Social Media companies include the following, EXCEPT: A. Charging a fee for their basic service level B. Advertising revenues...
Area 4: Management Please answer the following questions in a succinct and concise manner. Each answer...
Area 4: Management Please answer the following questions in a succinct and concise manner. Each answer should yield about 3-5 sentences. How would you explain the difference between Transactional and transformational leaders? Describe the major functions of Managers. Define SWOT analysis and explain how to apply it in a business situation or setting. Area 5: Management Information Systems Please answer the following questions in a succinct and concise manner. Each answer should yield about 3-5 sentences. What are the two...
1) Trace a drop of blood from the renal artery to the renal vein. Name all...
1) Trace a drop of blood from the renal artery to the renal vein. Name all the blood vessels. 2) How does filtrate form? What pressures are involved? What affect does each pressure have on formation? Trace a drop of filtrate from its formation to the point where it turns into urine. Explain ALL of the micro anatomy; and the physiology that occurs at each microanatomical structure along the way. 3) What would happen if HPg dropped by 16mm Hg?...
Hey i just read your comment and you just need to answer do you agree or...
Hey i just read your comment and you just need to answer do you agree or disagree with ir and explain My Teacher gave this answer and we need to response this answer You need to response this answer why you agree with it or why you disagree and explain You have Two Answer you need to response on your own word Reactions may include: feedback, agreements, disagreements, etc. with supporting facts, material, citations, etc. to support your reaction (or...
QUESTION 3 An electric utility operates in a state with right-to-work laws. About three-quarters of its...
QUESTION 3 An electric utility operates in a state with right-to-work laws. About three-quarters of its line workers have elected to join the union that represents them. Joel, one of the line workers, believes that his supervisor is unfairly passing him over when selecting employees to earn extra pay by working overtime. Joel wants to file a grievance according to the process in the labor agreement, but he is not a member of the union. What must the union do...
Edit question Psychology 251 ~. What are the advantages and disadvantages for children with visual and...
Edit question Psychology 251 ~. What are the advantages and disadvantages for children with visual and hearing impairments based on the age of initial occurrence? How does this affect your teaching strategy for the students? Briefly give examples. 2. Normally sighted children enter school with a great deal of knowledge about trees. How could a teacher help the young child who has been blind since birth (congenitally blind) develops the concept of trees? 3. How would you explain the sound...
Part 1: Identify two professional challenges Briefly describe five professional challenges that you currently face or...
Part 1: Identify two professional challenges Briefly describe five professional challenges that you currently face or anticipate facing soon. Then, rephrase each of those challenges as questions. Choose the two questions from your list that you feel are the most robust and challenging for you. Provide rationale for your choice of questions. Part 2: Create your mind maps for each question Use a mind map to create a separate map for each question. You may refer to your MindTool mind...
Can you reply to these replies from the question? Explain how the application of spreadsheets could...
Can you reply to these replies from the question? Explain how the application of spreadsheets could differ between a product-driven organization and a service-driven organization. Conduct your own research and provide specific examples to illustrate your ideas. “I think that a product based spreadsheet would contain information based on inventory levels, re-order levels, cost, sales price, quantity of sales and similar tracking information. A service based spreadsheet would contain information on customers, sales amount by customer, product sales by customer,...