Evidence Evidence eliminates file slack evidence.
About File Slack.
File slack is a data storage area of which most computer users
are unaware. It is a source of significant 'security leakage'
and consists of raw memory dumps that occur during the work
session as files are closed.
The data dumped from memory ends up being stored at the end
of allocated files, beyond the reach or the view of the computer
user. Specialized forensic tools are required to view and evaluate
file slack and it can prove to provide a wealth of information
and investigative leads. Like the Windows swap file, this source
of ambient data can help provide relevant key words and leads
that may have previously been unknown.
On a well used hard disk drive, as much as 900 million bytes
of storage space may be occupied by file slack. File slack should
be evaluated for relevant key words to supplement the keywords
identified in the steps above.
Such keywords should be added to the computer investigator's
list of key words for use later.
Because of the nature of file slack, specialized and automated
forensic tools are required for evaluation. NTI has created
a forensic utility called GetSlack that captures file slack
from hard disk drives and floppy disks. The output from the
GetSlack program can be evaluated in the same fashion as a Windows
swap file using the intelligent filter programs listed above.
File slack is typically a good source
of Internet leads.
The Evidence Eliminator Program will totally
eliminate file slack space, unrecoverable with forensic tools.
Of course this is just one of the many
pc security features of Evidence Eliminator.