Scalpel - File Carving from Partially Wiped Evidence Disk

On the previous article on proper information disposal, a visitor suggested that Darik's Boot and Nuke (DBAN) can be used for emergency evidence destruction. While it is quite correct, DBAN takes time to finish. So, what evidence can be recovered from a disk on which someone interrupted the DBAN process?

Example Scenario
We created a simulation of an interrupted information destruction. Here is the scenario:
An employee has been collecting illegal material on his corporate computer.

  • The employee is accidentally notified that internal audit investigators will review his computer in several minutes
  • The employee boots to a Darik's Boot and Nuke to destroy the disk contents
  • The investigators intercepts and disconnect the power to the computer before DBAN finishes

Since DBAN will overwrite information, it can be assumed that the File Allocation Tables are destroyed, as well as some of the data.
  1. The investigator creates a DD image of the disk drive, as presented in the Tutorial - Computer Forensics Evidence Collection
  2. The DD image is loaded into the Helix investigator computer
  3. All strings are extracted from the image using the 'strings' command - this activity creates a huge file that needs to be analyzed manually
  4. All possible files are extracted using the 'scalpel' file carving tool - this is an automated tool which can search for a lot of known file types and tries to extract them by matching the beginning and end of the file
  5. The carved files and strings are analyzed one by one. Most of the carved files are useless, since there is fragmentation on every drive so part of the files are lost, or the carving tool cannot match the other parts of the file.

  • While evidence recovery from a partially wiped drive is possible, it is both difficult and time consuming to achieve. At any rate, no investigator can guarantee successful results.
  • Also, it must be noted that after the first pass of the DBAN write, a very large percentage of information is already destroyed, so one has to be very lucky to walk in on the person while he/she is wiping the hard drive and interrupt the process on time.

Talkback and comments are most welcome

Related posts
New Helix3 Forensic CD - Welcome
Competition - Computer Forensic Investigation
Tutorial - Computer Forensics Evidence Collection
Tutorial - Computer Forensics Process for Beginners


juragan swike said...

I Know it's an old challange, but I just getting started in forensic, if it is not too much trouble, could you upload the image again? the link is broken.

thank you very much

juragan swike said...

sorry, wrong place. I meant to post at the forensic challange.

Anonymous said...

good Mouse button computer keyboard Integration.Cell/desktop sync potential. Click Here for Home windows Personal computer, without the pursuing update. nice.

Anonymous said...

good long-pressing on a encounter within the perspective finder. Snapchat Ghost Emojis demolished was made a decision by the sender. nice.

Festival Blog said...

Happy diwali Images
Happy Dhanteras
happy diwali photos
happy diwali quotes
happy Diwali image
happy Diwali Picture
Diwali images

lewismichael said...

good you could stream the video recording from many over Terrarium TV Television set iphone app which is normally nice.

Ethel Graff said...

Great was "thrilled by the owner's capability to transform marketed to straight by those musicians Fine.

kathiencarroll said...

good the earliest to the most recent or according to the genre App is not readily available for iPad as well as apple iphone nice.

uber customer care said...

uber customer care uber customer care contact number uber toll free contact number uber customer care hyderabad uber customer care email id

paytm customer care said...

paytm customer care paytm customer care email ID paytm customer care number paytm customer care number toll free number india paytm customer care number toll free

abdul muteeb said...

Amazing website thanks for sharing this wonderful information. windows 7 loader

Golden Gang said...
This comment has been removed by the author.
Golden Gang said...

this is the nice site keek it up
Mackeeper Crack

Muhammad Adnan said...

this is nice site thanks for sharing
matlab crack mac

Honey Malik said...

Nice post i really like it.
family law solicitors near me

Honey Malik said...

this is nice site thanks for sharing.
rohani ilaj contact number

kettyperry said...

when i visiting this site I found cool and interesting here keep sharing kindly check it out
download framaroot apk file

weight loss said...

thanks for sharing

Designed by Posicionamiento Web