Forensic analysis of anti-forensic file-wiping tools on Windows

Rayed AlHarbi1, Ali AlZahrani1, Wasim Ahmad Bhat1,2

  • 1Faculty of Computer & Information Systems, Islamic University of Madinah, Madinah, Saudi Arabia.

Summary

Forensic analysis of anti-forensic file-wiping tools on Windows reveals that file system metadata and Windows Registry keys retain evidence. This evidence helps identify tools used and remnants of wiped files, even after attempted deletion.