Windows Forensic Analysis is dedicated to sharing information pertinent to incident response and computer forensic analysis of the Windows NT+ family of operating systems. Topics can cover live response, forensic analysis, Registry or memory analysis, etc.
... Does blkls extract fileslack? We recently had a case where the system was running Windows 2000 and using a FAT32 partition on a 30GB hard drive. Analysing
It's better to show than tell. Here is a screenshot of the acquired image in Encase. As you see: No encryption. Arild Bjørk ... It's better to show than tell.
Arild, ... That is to be expected. I've acquired laptop hard drives where the corporate policy is full disk encryption...which means to get something you can