Scan of the Month |
|
Forensic Analysis of A Recovered Diskette Introduction |
|
|
The February 2003 Scan 26 is a computer forensics analysis of a floppy disk the police recovered from Jimmy Jungle's appartment. Jimmy Jungle supplies Joe Jacobs, the drug dealer arrested in Scan 24. This analysis is a continuation of the Scan 24 case. The police prepared an image from the recovered floppy. All references to a floppy disk or diskette in this report refer to this image. The police have tasked us to analyse the image, recover data and answer six questions including a bonus question. In our reports we must include where the findings are located on the floppy, what processes and techniques we used to decode the disk,and any intentional steps Jimmy Jungle may have taken to delete, hide and/or alter data on the diskette. The links to various parts of this document are in the table of contents frame to the left. The following paragraphs explain how to use the document. The questions and answers are found in the "Answers" section of the Scan 26 Report. The remaining sections of the "Scan 26 Report" include the technical detail that was necessary to the analysis. In the section, "Jungle's Wizardry" are the methods Jimmy Jungle may have taken to delete, hide and/or alter data on the diskette. Technical details can be found both in the "Forensic Process" and in the "File Offsets" section. The "Forensic Process" describes the order and approach to solving the data recovery problem. "Jungle's Wizardry" gives technical detail as it pertains to FAT and root directory issues. The "File Offsets" section includes a diagram and explanation of where files were found on the floppy. Concluding remarks are found at the end of the report. The "Reference" links have been included as useful supporting information. The "Recovered Files" JPEG, BMP and Text links display information harvested from the image. Although the recovered BMP file is available a JPEG version of it is also included for browsing convenience. The "Scan 24 Links" and the "Scan 26 Links" are intended for convenient referencing.
|