whereisyourdata

Use of forensic tools and technology, including: EnCase FTK WinHex Paraben Data Recovery Tools

Computer Forensics: Tracing an Email (Hotmail)

A video guide on how to trace a hotmail

06-10
02:18

Computer Forensics: Date for a File (in the MFT)

Files can have many dates, the first 4 dates for a file (in the MFT) are shown in this video. Looking at the $Standard_Information Attribute within the MFT. The examination is conducted using EnCase. These dates are important for those conducting forensic examinations

05-31
06:26

Computer Forensics: What Happens When You Delete Files?

Computer Forensics - What happens when a file is deleted?

05-02
03:33

WikiLeaks: How to upload to WikiLeaks

How to use WikiLeaks secure site.

04-19
03:08

Computer Forensics: Examining a Wiped Drive with EnCase

What happens when a drive is wiped? Can the data be recovered? What can computer forensics find? This short video looks at a wiped hard drive with EnCase

03-04
01:53

Computer Forensics: FTK Keyword Searching

Using the popular computer forensics tool, FTK 1.x to keyword search a small set of data.

02-01
04:00

Computer Forensics: Opening an EnCase E01 File

How to open an EnCase E01 File

02-01
02:16

Open hard drive in a bell jar with data activity LEDs

Open, working, hard disk drive running inside a glass bell jar... with data activity speed LED's!

12-04
01:37

MSN Encryption Part 2

Can you secure MSN? Does the encryption work?

10-04
02:29

MSN Encryption Part 1

Is it possibly to have a private conversation on a public network? Is MSN secure, if not can it be made secure?

10-04
09:13

Tor Beginners Guide (Part 1)

An introduction to "Tor". Tor is well known for hiding/anonymising IP addresses, but does it work, and can it be used?

09-27
03:56

Encase: Viewing Resident Data

Viewing resident and non resident data (i.e data within the MFT) with EnCase

09-19
02:34

Computer Forensics: Recovering Deleted Files With Encase

Recovering a deleted file with Encase, from an NTFS formatted USB drive

09-18
02:37

Computer Forensics: Examining File Slack with EnCase

Demonstrating File slack with with EnCase. File slack can, sometimes, contain information relevant to a case. Even if it does not its important for computer forensics examiners to understand the difference between active files, deleted files, and slack hits.

08-31
03:49

EnCase: Basic Keyword Searching

Very basic keyword searching guide for EnCase users

08-28
05:19

Encase: Locating the MFT from the Volume Boot

Manually locating the MFT and MFT Mirror from the Volume Boot, using EnCase

08-28
03:59

Encase: Manually locating the partition information from the MBR with EnCase

Locating the first partition, manually, using Encase

08-27
01:07

Encase: Examing the MBR with Encase

Examining the MBR with EnCase, to locate and identify the partition information

08-26
00:50

Recommend Channels