Page 1
WINDOWS FORENSICS · A GUIDE FOR UK LAWYERS What Evidence Can Be Recovered from a Windows Computer? Deleted Files, USB History, Logins, Browsing, Execution Traces and the Timeline They Build COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM 35 and CrimPR Part 19. Its e Discovery arm, e-discovery.uk, integrates device-level findings into disclosure-scale COURT-EXPERIENCED EXPERT WITNESSES
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the machine remembers 03 Deleted files and where they hide 04 USB devices and external media history 05 Logins, accounts and who was at the keyboard 06 Files opened, folders browsed: the recency artefacts 07 Programs run: the execution artefacts 08 Browsing, search in g and the online record 09 Event logs and the system's own diary 10 Building the timeline: from artefacts to narrative 11 Worked examples 12 Common mistakes and technical limitations 13 Questions to ask · Suggested wording 14 Checklist and red flags · When to involve a digital forensic expert 15 Frequently asked questions 16 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: WINDOWSRECORDSFARMORETHANUSERSCREATE
§ 02 · FIRST PRINCIPLES The problem in plain English: the machine remembers
§ 03 · WHATDELETIONLEAVES Deleted files and where they hide
Page 2
§ 04 · THEPLUG - INRECORD USB devices and external media history
§ 05 · WHOWASSIGNEDIN Logins, accounts and who was at the keyboard
§ 06 · WHATWASOPENED Files opened, folders browsed: the recency artefacts
§ 07 · WHATWASRUN Programs run: the execution artefacts
§ 08 · THEONLINERECORD Browsing, search in g and the online record
§ 09 · THE SYSTEM ' SDIARY Event logs and the system's own diary
Page 3
§ 10 · ASSEMBLY Building the timeline: from artefacts to narrative
§ 11 · IN THE WILD Worked examples EXAMPLE1 · THELEAVER, THESTICKANDTHEFIFTEENMINUTES EXAMPLE2 · THEDELETIONTHATPROVEDMORETHANTHEDOCUMENTSWOULDHAVE EXAMPLE3 · THESHAREDOFFICECOMPUTERANDTHEACCOUNTTHATWASNOTHIM
§ 12 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 13 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTION FOR A WINDOWS EXAM IN AT I ON
§ 14 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The Windows evidence checklist Red flags When to involve a digital forensic expert 35 / CrimPR Part 19 report that presents convergence a court can act on. Defensively, instruct an examiner
§ 15 · COMMON QUESTIONS Frequently asked questions Can deleted files really be recovered, and for how long? Can the computer prove who was using it, rather than which account? If someone used a wiping tool, is the evidence gone? The laptop has been used for months since the events. Is exam in at i on point less? Does any of this work on a Mac, or on cloud-stored files? What does a Windows exam in at i on cost and how long does it take?
Page 4
§ 16 · REFERENCE Glossary SRUM Sources and authoritative references DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
Cite as: Joseph Naghdi, What Evidence Can Be Recovered From A Windows Computer (1), Computer Forensics Lab, https://e-discovery.uk/library/what-evidence-can-be-recovered-from-a-windows-computer-1/pdf.
