Forensics Investigation of Deleted Files in a Drive

First of all download the OSForensics from here.

Select Create Signature Option. Click on Config 

Now browse the desired Directory from Directory list management, in my case I am selecting Desktop.

Click on Add to list Option to include the directory. Click OK

Now in start folder option, it will show us the selected Drive i.e. c:usersrajdesktop. Click on the Start Option.

It will ask for the File Name, enter the File Name & click on Save. So signature for data drive will be created.

Now does some modification in data drive and repeat the same steps to create another signature after modifications in data drive.

Now click on Compare Signature Option.

Browse both files i.e. Old Signature as well as New Signature Option.

Click on Compare option .It will start the process. Now it will show us the files with their modification status as well as their creation and modification date. We can select show option to see only modified or deleted files.

Now it will show only deleted or modified files with their creation and deletion date.

AuthorMukul Mohan is a Microsoft Certified System Engineer in Security and Messaging. He is a Microsoft Certified Technology Specialist with high level of expertise in handling server side operations based on windows platform. An experienced IT Technical Trainer with over 20 years’ Experience. You can contact [email protected]

Leave a Reply

Your email address will not be published. Required fields are marked *