Related Experiment Video
Updated: Oct 17, 2025

Standardized Method for Measuring Collection Efficiency from Wipe-sampling of Trace Explosives
Published on: April 10, 2017
Forensic analysis of anti-forensic file-wiping tools on Windows
Rayed AlHarbi1, Ali AlZahrani1, Wasim Ahmad Bhat1,2
1Faculty of Computer & Information Systems, Islamic University of Madinah, Madinah, Saudi Arabia.
Forensic analysis of anti-forensic file-wiping tools on Windows reveals that file system metadata and Windows Registry keys retain evidence. This evidence helps identify tools used and remnants of wiped files, even after attempted deletion.
Area of Science:
- Digital Forensics
- Computer Science
Background:
- File-wiping tools are used to permanently delete data, posing challenges for digital investigations.
- Understanding how these tools interact with file systems is crucial for evidence recovery.
Purpose of the Study:
- To conduct a forensic analysis of anti-forensic file-wiping tools on the Windows operating system.
- To identify and extract evidence of file-wiping tools and their targets within Windows file systems.
Main Methods:
- Analysis of metadata structures in FAT32, exFAT, and NTFS file systems after file wiping.
- Examination of Windows Registry keys and .lnk files for forensic artifacts.
- Experimentation with four specific file-wiping tools: SecureDelete, Secure Eraser, PC Shredder, and Blank and Secure.
Main Results:
- FAT32/exFAT directory structures and NTFS $MFT entries can confirm tool usage and identify tools, preserving file remnants.
- $LogFile and $UsnJrnl files in NTFS, along with Windows Registry keys, provide detailed evidence of tools and wiped files.
- Alternate Data Streams, $LogFile, $UsnJrnl, and Registry keys were found to be not wiped by the tested tools.
Conclusions:
- File system metadata and Windows Registry keys are valuable sources for detecting anti-forensic tool usage and recovering data remnants.
- Specific artifacts within NTFS ($MFT, $LogFile, $UsnJrnl) and Registry keys offer robust evidence trails.
- The study highlights limitations and suggests future research directions in digital forensics for file-wiping tool analysis.
More Related Videos
11:49Enhanced Genetic Analysis of Single Human Bioparticles Recovered by Simplified Micromanipulation from Forensic ‘Touch DNA’ Evidence
Published on: March 9, 2015
03:07Scanning Electron Microscopic Evaluation of Surface Defects of Remover Retreatment File After Single and Multiple Uses
Published on: October 11, 2024
Related Concept Videos
Sample Preparation for Analysis: Advanced Techniques
Acid digestion with strong acids is commonly used to dissolve inorganic materials that are insoluble (do not dissolve) in water. This method can be useful for...
Sample Preparation for Analysis: Overview
Bulk or large solid samples are typically reduced in size using grinding, crushing, or milling techniques to increase the...