Related Experiment Video
Updated: Oct 5, 2025

Standardized Method for Measuring Collection Efficiency from Wipe-sampling of Trace Explosives
Published on: April 10, 2017
Digital forensic investigation methodology for Storage Space: Based on the NIST digital forensic process
Junho Kim1, Sangjin Lee1, Doowon Jeong2
1School of Cybersecurity, Korea University, Seoul, South Korea.
Digital forensic examiners face challenges with software-based RAID, like Storage Space. This study details Storage Space structure and provides an automated tool for virtual disk reconstruction in forensic investigations.
Area of Science:
- Digital Forensics
- Computer Science
- Information Security
Background:
- Investigating server RAID systems presents challenges for forensic examiners due to the need to reconstruct multiple high-capacity disks.
- The increasing use of software-based RAID in personal computers necessitates forensic consideration of these systems.
- Limited research exists on digital forensic methodologies for software-based RAID, such as Microsoft Storage Space.
Purpose of the Study:
- To detail the structure of Microsoft Storage Space through reverse engineering.
- To develop an automated tool for reconstructing virtual disks configured with Storage Space.
- To provide a basis for forensic investigations involving Storage Space.
Main Methods:
- Applied the National Institute of Standards and Technology (NIST) digital forensic process to analyze Storage Space.
- Performed reverse engineering to understand the underlying structure of Storage Space.
- Developed and evaluated an automated tool for virtual disk reconstruction.
Main Results:
- Successfully reverse-engineered and detailed the structure of Storage Space.
- Developed a functional automated tool capable of reconstructing Storage Space virtual disks.
- Demonstrated the effectiveness of the developed methods and tool through an experimental scenario.
Conclusions:
- The detailed analysis and developed tool provide crucial forensic capabilities for Storage Space.
- This research establishes a foundation for digital forensic investigations of software-based RAID systems like Storage Space.
- The findings are essential for examiners investigating digital evidence on personal computers utilizing Storage Space.
More Related Videos
07:57Quantitative Detection of Trace Explosive Vapors by Programmed Temperature Desorption Gas Chromatography-Electron Capture Detector
Published on: July 25, 2014
05:31Gas Chromatography-Mass Spectrometry Paired with Total Vaporization Solid-Phase Microextraction as a Forensic Tool
Published on: May 25, 2021
Related Concept Videos
Archival Research
Storage
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security: