Evidence Evidence overwrites unallocated space evidence.
Unallocated Space (Previously Deleted Files).
The DOS and Windows 'delete' function
does not completely erase file names or file content.
Many computer users are unaware the storage space associated
with such files merely becomes unallocated and available to be
overwritten with new files.
Unallocated space is a source of significant
'security leakage' and it potentially contains erased files
and file slack associated with the erased files.
Often the DOS Undelete program can be used to restore the previously
erased files. Like the Windows
swap file and file
slack, this source of ambient data can help provide relevant
key words and leads that may have previously been unknown to the
computer investigator.
On a well used hard disk drive, millions of bytes of storage
space may contain data associated with previously deleted files.
Unallocated space can be evaluated for relevant
key words to supplement the keywords identified in the steps above.
Such keywords can be added to the computer investigator's list
of key words for use in the next processing step.
Because of the nature of data contained in unallocated space
and its volume, specialized and automated forensic tools are required
for evaluation. Forensic specialists have utilites that quickly
capture all unallocated space from hard disk drives and floppy
disks.
The output from these programs can be evaluated in the same fashion
as the other types of ambient data mentioned previously using
intelligent filter programs.
Unallocated space is typically a good source of data that was
previously associated with word processing temporary files and
other temporary files created by various computer applications.
It is also a good source of leads concerning graphics files that
have been viewed over the Internet and Forensic software can be
used very effectively to identify these graphic file remnants
left behind in unallocated storage space.
The Evidence Eliminator Program will totally eliminate unallocated
space, unrecoverable with forensic tools.