Skip to main content

Finding Artifacts

  • Chapter
  • First Online:
Fundamentals of Digital Forensics
  • 2462 Accesses

Abstract

The essence of any forensic examination is to look for data, artifacts. While it is impossible to describe all possible artifacts that may be of interest in any given investigation, this chapter aims to describe how to find some artifacts that are very common to look for. The chapter first describes how to find information such as install date and time zone settings from the Windows registry. Next, the chapter provides a rather detailed description of how to analyze a partition table in order to ensure that all drive space is allocated to a partition. An overview of how to search for deleted files is also included. A lot of good information can be found in file metadata, which includes information such as when a file was created and by whom. Analyzing different kinds of metadata is described before the chapter presents an approach on how to analyze log files. At the end of this chapter is a discussion on how to analyze unorganized data such as unpartitioned disk space or slack.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 44.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 59.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Notes

  1. 1.

    https://sqlitebrowser.org/dl/

References

Download references

Author information

Authors and Affiliations

Authors

Rights and permissions

Reprints and permissions

Copyright information

© 2020 Springer Nature Switzerland AG

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Kävrestad, J. (2020). Finding Artifacts. In: Fundamentals of Digital Forensics. Springer, Cham. https://doi.org/10.1007/978-3-030-38954-3_14

Download citation

  • DOI: https://doi.org/10.1007/978-3-030-38954-3_14

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-030-38953-6

  • Online ISBN: 978-3-030-38954-3

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics