Digital tool marks (DTMs): a forensic analysis of file wiping software
Whilst difficult to ascertain the full extent to which so called anti-forensic software applications are in use by the public, their threat to an investigation of digital content is tangible, where of particular interest is the use of file wiping tools, which remains the focus of this work. This wor...
Saved in:
Published in | Australian journal of forensic sciences Vol. 53; no. 1; pp. 96 - 111 |
---|---|
Main Author | |
Format | Journal Article |
Language | English |
Published |
Clovelly
Taylor & Francis
02.01.2021
Copyright Agency Limited (Distributor) |
Subjects | |
Online Access | Get full text |
ISSN | 0045-0618 1834-562X |
DOI | 10.1080/00450618.2019.1640793 |
Cover
Loading…
Summary: | Whilst difficult to ascertain the full extent to which so called anti-forensic software applications are in use by the public, their threat to an investigation of digital content is tangible, where of particular interest is the use of file wiping tools, which remains the focus of this work. This work presents the examination of eight freely available wiping tools in order to identify the existence of 'digital tool marks' (DMTs) left on a system following their use. Further attempts are made to ascertain whether such DTMs can be attributable to a particular wiping tool. Analysis is focused on the impact each tool has on system at a file system level, where in this work both FAT32 and NTFS are the subject of investigation. DMTs relating to each wiping tool are provided and recoverable file system metadata post-wipe is described. |
---|---|
Bibliography: | 2021-01-16T17:53:40+11:00 AUSTRALIAN JOURNAL OF FORENSIC SCIENCES, Vol. 53, No. 1, Feb 2021, 96-111 TAJFS.jpg AUSTRALIAN JOURNAL OF FORENSIC SCIENCES, Vol. 53, No. 1, Feb 2021: 96-111 Informit, Melbourne (Vic) ObjectType-Article-1 SourceType-Scholarly Journals-1 ObjectType-Feature-2 content type line 14 |
ISSN: | 0045-0618 1834-562X |
DOI: | 10.1080/00450618.2019.1640793 |