Title: Digital Forensic Analysis of Hard Disk for Evidence Collection

Issue Number: Vol. 7, No. 2
Year of Publication: Jun - 2018
Page Numbers: 100-110
Authors: Bandu B. Meshram, Dinesh N. Patil
Journal Name: International Journal of Cyber-Security and Digital Forensics (IJCSDF)
- Hong Kong
DOI:  http://dx.doi.org/10.17781/P002372


As the Computers have become a common things ranging from house to the industry, the crimes which are associated with it also have increased tremendously. By performing the digital forensic analysis, it is possible to identify the types of crime committed and the criminal behind the crime. The Computer hard disk is a main source of evidence against such crimes as it maintains the digital information on it. The evidence against the criminal can be identified by performing the digital forensic investigation of the file system on the hard disk. As certain sensitive or malicious information might be hidden by the suspect in the free space or the slack space of the file system this raises the need to do the forensic investigation of these spaces and to retrieve the sensitive information and metadata associated with it to identify the criminal. This paper proposes an approach to extract the hidden information. A new approach to recover the deleted data is also proposed. The proposed approaches are implemented in a tool