Sažetak
When forensic analysis of the Windows operating system and the search for the existence of suspected files, applications, or artifacts of the operating system, the process of restoring deleted data is very often hard drives (SSD) SATA or NVMe interfaces in personal computers and taking into account properties such as wear leveling and garbage collection solid state hard drives, it is significantly difficult to recover deleted data as well as proving the start and presence of suspected files on the computers of the attacker or victim. This article analyzes the Windows Windows Search feature with a linked Windows.edb file as well as the 3rd Party application for indexing operating system files to find records of suspect files, metadata, applications, and their activities relevant to forensic analysis.
Ključne riječi
digital forensic ; Windows indexing system ; database ; file recovery tools ; record recovery tools.