Back to Search Start Over

Artifacts of CD Burning in the Microsoft Windows Master File Table

Authors :
B A Douglas Elrick
Source :
Journal of Forensic Sciences. 57:103-107
Publication Year :
2011
Publisher :
Wiley, 2011.

Abstract

When theft of a physical item occurs it is detectable by the fact that the object is missing, however, when the theft of a digital item occurs it can go unnoticed as exact replicas can be created. The original file is left intact but valuable information has been absconded. One of the challenges facing digital forensic examiners is detecting when files have been copied off of a computer system in some fashion. While certain methods do leave residual evidence behind, CD Burning has long been held as a copying method that cannot be identified. Through testing of the burning process and close examination of the New Technology File System (NTFS), artifacts from the master file table in the various versions of Microsoft Windows, markers have been found that are associated with copying or “burning” files to CD or DVD. Potential evidence that was once overlooked may now be detectable.

Details

ISSN :
00221198
Volume :
57
Database :
OpenAIRE
Journal :
Journal of Forensic Sciences
Accession number :
edsair.doi...........1ad4d9e70d5f114c5bcbe28bb54b7917
Full Text :
https://doi.org/10.1111/j.1556-4029.2011.01919.x