Recycle Bin Forensics

Поделиться
HTML-код
  • Опубликовано: 21 янв 2025

Комментарии • 28

  • @jacobconeby1466
    @jacobconeby1466 9 месяцев назад

    This is great! Thank you for all the hard work in putting these videos together.

  • @4n6wizard
    @4n6wizard 6 лет назад +3

    Another great video, well done, clear and straight forward information.
    Thanks.

  • @user-jx2kg2er5o
    @user-jx2kg2er5o 6 лет назад +1

    This guy does GREAT forensics work!

  • @MoradRawashdeh
    @MoradRawashdeh 4 года назад +2

    Man I like you work ... I have a strange question.
    At 7:02 you made a zoom while you are recording ... what is the screen recorder and the editing software you used ??

    • @13Cubed
      @13Cubed  4 года назад +2

      Thanks! ScreenFlow was used for much of the early work. I still use it today, but just for the basic screen recordings. I use Final Cut Pro X to do everything else.

    • @MoradRawashdeh
      @MoradRawashdeh 4 года назад

      @@13Cubed thanks for the answer

  • @xDx4444
    @xDx4444 2 года назад +1

    Nice video brother ;) Subscribed!

  • @rohithkalvala8934
    @rohithkalvala8934 5 лет назад +1

    with all do respect could you clarify what is the difference between this tool and autopsy ? as it shows same detailed information about deleted files.

  • @lukehampson4280
    @lukehampson4280 5 лет назад +1

    thanks! super interesting. handy to see wmic cmd as well.

  • @robinhood3841
    @robinhood3841 4 года назад

    Is there a way to recover the files that been deleted for example the files deleted using shift + delete etc ?

    • @13Cubed
      @13Cubed  4 года назад

      Not from Recycle Bin, but they would be in unallocated space until overwritten, or potentially within any volume shadows present on the system.

    • @robinhood3841
      @robinhood3841 4 года назад

      @@13Cubed so please can you tell me how to recover it or from where , and thanks a lot

    • @13Cubed
      @13Cubed  4 года назад +3

      Robin Hood Watch the episodes covering volume shadows - those should help you; or try various file recovery software like PhotoRec.

    • @robinhood3841
      @robinhood3841 4 года назад +1

      @@13Cubedthank you very much !

  • @emran5897
    @emran5897 6 лет назад

    Really Great video............
    Thanks For sharing the knowledge...............

  • @RBSRG
    @RBSRG 5 лет назад +1

    Awesome video however please forgive my ignorance. What use is this in a forensic scenario? As when the file is emptied from trash the $r $i files are removed too or at least from within this scope. Which makes this technique obsolete?

    • @13Cubed
      @13Cubed  5 лет назад

      Often, the Recycle Bin folders are not emptied. I've encountered this numerous times in investigations. Additionally, one may be able to recover (carve) files from unallocated space.

    • @RBSRG
      @RBSRG 5 лет назад

      Thank you!

    • @MuhammadAli-dk6dz
      @MuhammadAli-dk6dz 4 года назад

      @@13Cubed I have $ index files from before when I emptied the recycle bin but I can't find $ index for files I deleted this morning. Why some $ index files are available after permanent deletion and not others.

  • @volkanyildrim6627
    @volkanyildrim6627 5 лет назад +1

    Great video!
    You can use 7-Zip in Admin mode to visit the folder and so on

  • @charlesmullen8024
    @charlesmullen8024 6 лет назад

    Very informative.

  • @SecureTheWorld
    @SecureTheWorld 6 лет назад

    Can you make a full in-depth video about browser forensics.

    • @13Cubed
      @13Cubed  6 лет назад +4

      I will add this to my suggestions list. I would probably do a video per browser, as a single video covering all of the major vendors would be very long.

    • @SecureTheWorld
      @SecureTheWorld 6 лет назад

      13Cubed really appreciated for the great efforts. i have a question to ask. If someone accessed a file on remote server then deleted it what evidence we can pull from server side and client side to confront him.

    • @13Cubed
      @13Cubed  6 лет назад

      Server-side, it depends on whether or not you have an object access audit policy configured to generate logs for that activity. Client-side, there are numerous ways to determine whether a file was opened or a particular folder was accessed -- Shellbags and LNK files would be one of the first things that come to mind.

    • @SecureTheWorld
      @SecureTheWorld 6 лет назад

      13Cubed i have tried shellbags it shows folders. LNK files i think its there but didnot have a tool to check i just saw it and could not open or check the file info because its been deleted. Please if you have more artifacts later add it please . Thanks alot for the great help

  • @YumPwncakezPS
    @YumPwncakezPS 7 лет назад

    Super

  • @TheKiller7276
    @TheKiller7276 7 лет назад

    neat