Unit Ii CF
Unit Ii CF
Bootstrap process
Contained in ROM, tells the computer how to proceed
Displays the key or keys you press to open the CMOS setup screen
CMOS should be modified to boot from a
forensic floppy disk or CD
Understanding the Boot Sequence
(continued)
Understanding Disk Drives
Disk drives are made up of one or more
platters coated with magnetic material
Disk drive components
Geometry
Head
Tracks
Cylinders
Sectors
Understanding Disk Drives
(continued)
Data streams
Ways data can be appended to existing files
Can obscure valuable evidentiary data, intentionally or by coincidence
In NTFS, a data stream becomes an additional
file attribute
Allows the file to be associated with different applications
You can only tell whether a file has a data
stream attached by examining that file’s MFT
entry
NTFS Compressed Files
NTFS provides compression similar to FAT
DriveSpace 3
Under NTFS, files, folders, or entire volumes
can be compressed
Most computer forensics tools can uncompress
and analyze compressed Windows data
NTFS Encrypting File System
(EFS)
Encrypting File System (EFS)
Introduced with Windows 2000
Implements a public key and private key method of encrypting files, folders, or
disk volumes
When EFS is used in Windows Vista Business
Edition or higher, XP Professional, or 2000,
A recovery certificate is generated and sent to the local Windows administrator
account
Users can apply EFS to files stored on their
local workstations or a remote server
EFS Recovery Key Agent