Lab 2 Recover Deleted Files From Drive
Lab 2 Recover Deleted Files From Drive
files
Introduction:
The first step in a digital forensic investigation is to create a forensic image, you can either
create an image of the whole physical drive or an image of a part within the drive.
Physical hard disk stores data and it comes with free spaces without any partitions. We can
create virtual hard disk in theses free spaces, each partition is treated separately, and you
can install a sperate OS on the same physical hard disk [1].
The logical drive is the disk part that interacts with the user and has a name, file system,
and size. You create different logical drives with different sizes, however, they all will
remain part of the same physical disk. Each logical drive can have its own file system.
Software Used:
1- Windows 10 VM.
2- Access FTK Imager
3- Autopsy
Lab Objectives:
1- Understand how to create a virtual hard drive.
2- Make a copy of the created VHD (image).
3- Recover deleted files, even if the file is deleted permanently from the system.
1- Right -Click on (This PC) within File Explorer and select the (Manage option).
https://academy.cyber5w.com/courses/take/working-virtual-hard-
5- For our lab, we will be using a virtual disk size of 100 MB. We are also going
to use both the VHD and Fixed Size (Recommended) options. To proceed
click the OK button.
9- The next window specifies the size of the volume; keep the default values
as it is and click Next button.
10- We need now to select the volume letter or use other options. In our
exercise we are going to use the letter E to attach the disk on and then click
Next.
Wait till the analysis is 100% done at the bottom of the page.
Discover the files in Autopsy such as Deleted Files, and File Type>>By Extension
etc..