Module 2-2 - Basic-Technical-For-Digital-Forensics
Module 2-2 - Basic-Technical-For-Digital-Forensics
Active Data
• Allocated
– Active data
– In use
– Can be seen by OS
• Unallocated
– No longer in use
– Slack space (Drive slack)
– Invisible to OS
Space on a Hard Drive
• Passwords
• Fragments of images or documents
• Anything else from RAM
• BUT there is no timestamp, so it will be hard
to connect to a specific user or event
Hiberfil.sys
http://fpt.edu.vn 05/20/24 23