Main Page

From ForensicsWiki
Revision as of 22:37, 12 December 2009 by Simsong (Talk | contribs)

Jump to: navigation, search

This is the Forensics Wiki, a Creative Commons-licensed wiki devoted to information about digital forensics (also known as computer forensics). We currently list a total of 863 pages.

Much of computer forensics is focused on the tools and techniques used by investigators, but there are also a number of important papers, people, and organizations involved. Many of those organizations sponsor conferences throughout the year and around the world. You may also wish to examine the popular journals and some special reports.

Selected Forensics Research


What happens when you overwrite data?.

Data recovery Craig S. Wright explores what happens when you try to cover overwritten data using high-quality scientific equipment. His conclusion: "The values do not tell you what existed on the drive prior to the wipe; they just allow you to make a guess, bit by bit. Each time you guess, you compound the error. As recovering a single bit value has little if any forensic value, you soon find that the cumulative errors render any recovered data worthless."


Linux for computer forensic investigators: «pitfalls» of mounting file systems (Russian version), Suhanov Maxim, 2009

The paper opens discussion about building forensically sound Live CD distributions based on Linux. Problems described:

  • Common misconceptions about "-o ro" mount option (is it forensically sound?);
  • Bugs in many forensic Live CDs that alter the data on evidentiary media.

Denis Frati (CAINE developer) wrote an excellent review (Italian) of the bug found in Casper scripts.

(Past selected articles are archived here.)


You can help! We have a list of articles that need to be expanded. If you know anything about any of these topics, please feel free to chip in.