Understanding $DATA attribute

Created: Thursday, 20 September 2018

The following scenario demonstrates a potentially confusing situation you might face as an investigator. Knowing extensively the NFTS internals will help you to reach at valid conclusions.

Assume that you have located a deleted...

Recovering a deleted file from FAT32

Created: Saturday, 25 August 2018

Assume you use a forensic software that has recovered file system metadata of a deleted jpeg file from a FAT32 formatted volume with a cluster size of 2.048 bytes. The forensic software displays that the recovered file has starting cluster...

Reconstructing a RAID 5 that holds an NTFS volume without knowing its configuration.

Created: Tuesday, 03 July 2018

To save readers' precious time I would like to emphasize the fact that that this guide applies in raids containing an NTFS formatted volume.

Firstly, keep in mind that this guide serves as a proof of concept, hopefully it will prove...

Questions on File Systems and Windows Forensics.

Created: Thursday, 09 March 2017

Below you will find questions that test your knowledge on this subject. I wrote them while I read material mainly from books in file systems and Windows Forensics.

The questions are not meant to be exhaustive and they might even...

About

Created: Sunday, 27 January 2013

Professional Experience

Since March 2012, I have worked as a Digital Forensics Examiner, handling a wide range of investigations, including:

  • Copyright infringement
  • Data...

Built with...

Created: Saturday, 05 January 2013

In May 2026, all backend libraries are updated, and the site moved to python3.14 rutime.

In March 2026, all backend and client libraries are updated, and the site moved to python3.14 rutime, minor changes to code occurred mainly for...

© 2012 - 2026 Armen Arsakian updated atThursday 28 May 2026Contact: contact at arsakian.com

-3261 . 5208:v0.85