Hi there. Today I am going to be showing you how to find files that have been deleted on a storage device (in our case, a flash drive). But before I can show you how to do this, I need to make sure that you are doing it in a digitally safe manner.
To follow along in this tutorial, you will need:
The Demo Version of\\Forensic Toolkit 1.81: Available Here
ThumbScrew Write-blocking freeware: Available Here
A copy of the flash drive we will be analyzing: Coming Soon
_________________________________________________________________________________
For the sake of this exercise, lets use the following scenario:
"A friend of ours, Theseus, has come to us with a concern. He fears that his girlfriend Helen, has been unfaithful to him. He brings us a flashdrive of hers, and asks us to see if we can find anything to confirm his suspicion."
So we begin.
First, we want to activate our write blocking software, ThumbScrew, on the computer we will use for the examination. In our computer's system tray, we click the the Thumbscrew Icon, choosing to make "USB read only"
What this will do is modify our computer's registry to prevent us from accidentally writing to Helen's USB flashdrive when we plug it into our computer. This is important because we want to return the flashdrive in the exact same way we found it. Forensically speaking, we are ensuring that the evidence will not be altered by our investigatory process. Now we can plug in Helen's flash drive.
Next, we need a productive way to look through the flashdrive. We could use Windows Explorer as our primary tool, but without special forensic software, our analysis options are very limited.
We will use Forensic Tool Kit. At the opening screen, we select the option that allows us to go directly into working in FTK.
When starting FTK, we will see this home screen. We go to FILE>ADD EVIDENCE and click NEXT twice.
We will be asked to choose the format of the evidence that you wish to add to the case. We want to select the "Physical Drive" option. Now, we can select Helen's flashdrive.
Once we have selected the flashdrive as evidence, we should see a screen that looks like this:
FTK has taken Helen's flashdrive, and has analyzed and organized all of the files on it. Just one problem though. What files? FTK is reporting that there is only a sole document file on the drive (with the exception of a few file system folders). Additionally, It shows that there are no deleted files on the flashdrive.
We can click on the "documents" tab in FTK, to see the file named "receipt.txt". the built in viewer in FTK allows us to read its contents- a simple receipt for a few purchases at the Greek Market Place". Not Something we could consider incriminating.
We double check in Windows Explorer, and sure enough, theres only that one document on the flashdrive. But wait! Before we tell Theseus anything, we need to take a closer look. Doesn't it seem odd that Helen would carry around a flashdrive with just a receipt on it?
Maybe she wiped or reformatted her flashdrive at some point before "receipt.txt" was made. After all, Helen is more tech-savvy than most. This would have performed an advanced delete on any files that were previously on the flashdrive. If there were any incriminating files, they would now be hidden from the flash drive's file directory- and wouldn't appear in any of FTK's categories.
To make sure we aren't missing anything , we need to take a look at the hexadecimal values of the flashdrive's storage space. To do this, select the "Total File Items" pane in FTK, and select the FAT1 storage area. Doing so will display the hexadecimal values for all of the files on Helen's flashdrive.

It seems suspicious that there is this much data present for only a single text file. So we think that Helen tried to get rid of something taht was once on the flashdrive, But how do we find out what it was?
We can make use of a tool in FTK that specializes in reading this kind of data. The tool is the data carver. To use it, We Select TOOLS>DATA CARVING, and press "okay" to the pop up box that appears. We have just instructed FTK to read and interpret the information that corresponds to files that we cannot see.
Sure enough, the data carving tool produces two files that were previously not view-able a .jpg file and a .pdf file-good thing we double checked. We can view either file by double-clicking.
Judging by the nature of the files, its probably best that we call Theseus and tell him the bad news.
The carved PDF file:
To preserve what we found, FTK allows us to add the carved files to the case, and then export them onto our computer.
________________________________________________________________________
I hope that this blog post has provided you with an insightful-yet easy to follow- guide to doing a basic file restoration from a storage device that has been reformatted. My next post will demonstrate how to crack open a password protected file.






Hey John, I would love to comment on your second blog post, but I don't see it yet. Also, the links are broken at the beginning of this post, but they work in the last post.
ReplyDelete