Started By
Message

Any computer forensics gurus out there?

Posted on 11/27/14 at 9:05 am
Posted by Powerman
Member since Jan 2004
162225 posts
Posted on 11/27/14 at 9:05 am
I've got a little situation at my place of employment that I'm trying to investigate

The scenario. Myself and another employee who I rotate with on an assignment share some information that we exchange on a hard drive.

A few weeks ago the hard drive was stolen. Didn't think much of it other than someone stealing a hard drive.

He gets another drive that he loads some info on for me. I took a look at the drive and didn't do much with the files my first few days. A couple days ago I insert the drive and someone has wiped it clean.

I was able to find a recovery program to retrieve the files, but I want to know who wiped all the files off the drive. Is there a way to look at the usage history of the drive (i.e. which machine would have wiped the data?)

I've been looking around to see if there is a program out there that is capable of this. I'm sure I could send it off to an expert if I wanted to take the investigation far enough. What are my options here?
Posted by Spock's Eyebrow
Member since May 2012
12300 posts
Posted on 11/27/14 at 9:18 am to
quote:

A few weeks ago the hard drive was stolen. Didn't think much of it other than someone stealing a hard drive.



Hope it was using FDE.

quote:

A couple days ago I insert the drive and someone has wiped it clean.

Is there a way to look at the usage history of the drive (i.e. which machine would have wiped the data?)


The point of "wiping a drive clean" is to restore it to brand-new condition, so almost certainly not. Your only hope would be for it not to have been wiped clean, and there are many programs to inspect drives, e.g. WinHex.
Posted by WPBTiger
Parts Unknown
Member since Nov 2011
31045 posts
Posted on 11/27/14 at 9:18 am to
If the drive was truly wiped, that is it was overwritten, I am not familiar with being able to determine this information.
Posted by Powerman
Member since Jan 2004
162225 posts
Posted on 11/27/14 at 9:28 am to
Well it wasn't completely wiped because I was able to undelete the files.

I suppose what I meant is this guy just deleted the items. He isn't tech savvy enough to know how to really wipe something.

This guy is a dumb arse. He is about to be an unemployed dumb arse if I can figure out how to prove he deliberately deleted the files. I know who did it, I just need to be able to prove it.
Posted by WPBTiger
Parts Unknown
Member since Nov 2011
31045 posts
Posted on 11/27/14 at 9:33 am to
If he was logged in to his account on the computer when the files were deleted, they should have a recycle bin number associated with his account.
Posted by Powerman
Member since Jan 2004
162225 posts
Posted on 11/27/14 at 11:25 am to
Would I be able to pull that info without getting into his computer?
Posted by Bestbank Tiger
Premium Member
Member since Jan 2005
71104 posts
Posted on 11/27/14 at 12:31 pm to
quote:

Would I be able to pull that info without getting into his computer?


Just inspect his computer (or have someone from management/HR present while the IT guy inspects it). It's company property and he has no expectation of privacy when it comes to that computer.
Posted by WPBTiger
Parts Unknown
Member since Nov 2011
31045 posts
Posted on 11/27/14 at 12:36 pm to
quote:

Would I be able to pull that info without getting into his computer?
quote:

Just inspect his computer (or have someone from management/HR present while the IT guy inspects it). It's company property and he has no expectation of privacy when it comes to that computer.


Outside of this, you would need to make an image of that hard drive and examine the image.
Posted by ADLSUNSU
Baton Rouge
Member since Sep 2007
3518 posts
Posted on 11/27/14 at 1:00 pm to
If his computer was on a domain, would there be a log of actions performed like above, and look for the old drive name maybe.

Posted by foshizzle
Washington DC metro
Member since Mar 2008
40599 posts
Posted on 11/27/14 at 1:05 pm to
quote:

Didn't think much of it other than someone stealing a hard drive.


What kind of work do you do that this is a commonplace occurrence? I've been in the workforce for 25 years and this has never happened to me.
Posted by Powerman
Member since Jan 2004
162225 posts
Posted on 11/27/14 at 2:05 pm to
quote:

What kind of work do you do that this is a commonplace occurrence?

It's not commonplace

It's offshore construction. A lot of different people in and out of the offices. Never had a problem with theft until this one incident. Which didn't really capture my interest until this other incident of someone deleting all of my shite.
Posted by Asgard Device
The Daedalus
Member since Apr 2011
11562 posts
Posted on 11/27/14 at 7:18 pm to
Something doesn't add up here.
Posted by ILikeLSUToo
Central, LA
Member since Jan 2008
18018 posts
Posted on 11/27/14 at 7:43 pm to
Theft is theft, but do you think the thief of the original HDD wiped your new one? How would that benefit him in any way?
Posted by Grassy1
Member since Oct 2009
6256 posts
Posted on 11/28/14 at 9:55 am to
All the same, you need to give us a few more details, just to make black Friday more interesting.

And be sure to update us upon his firing.
Posted by Powerman
Member since Jan 2004
162225 posts
Posted on 11/28/14 at 12:29 pm to
quote:

Theft is theft, but do you think the thief of the original HDD wiped your new one? How would that benefit him in any way?

Sabatoge

He seems like the type of guy that would like to get a leg up by cutting someone else's throat

I know he wants my job. But he's too much of a dumb arse to do it anyway so I'm not worried about that. I just don't want to work around someone that would engage in such underhanded behavior to get a leg up.
Posted by blue_morrison
Member since Jan 2013
5133 posts
Posted on 11/28/14 at 10:27 pm to
quote:

and someone has wiped it clean.


A drive is never truly wiped clean after one format. You really gotta do it several times until the binary is FUBAR to the computer so it's much harder to recover.
Posted by gmrkr5
NC
Member since Jul 2009
14891 posts
Posted on 11/29/14 at 6:12 am to
Lol thats wrong. Formatting a driven does not delete data.

The metadata of the files may show the user SID associated with the last modified time. If he just formatted the drive though you would need to analyze the computer it was done from. Should be able to correlate some events...
This post was edited on 11/29/14 at 6:15 am
Posted by blue_morrison
Member since Jan 2013
5133 posts
Posted on 11/29/14 at 9:09 am to
Several times with a good program.

That's advice given to me from an FBI guy. Now that I think about it...hmmmmmmm
Posted by gmrkr5
NC
Member since Jul 2009
14891 posts
Posted on 11/29/14 at 12:15 pm to
What he was probably referring to was several passes with a legit disk wiping utility such as DBAN. Your not recovering anything from a drive after that.
Posted by blue_morrison
Member since Jan 2013
5133 posts
Posted on 11/29/14 at 12:22 pm to
Yeah that was the name of it. Couldn't remember it.

He also recommended taking a hammer to the platters.
first pageprev pagePage 1 of 2Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram