When performing an analysis on a disk, or set of disks, there are signs that it may have touched other computers. Simply select a location to where the file should be saved and it will be extracted from the image that you are currently working with. In order to recover the files, you simply right-click on the file in question and select "Copy file. You can see this better in the example below. Any files that have been deleted, or were erased will be shown with a red-x on them. Once this segment has been selected, the same as we've discussed with Autopsy will hold true with this software. Advantages and Disadvantages of a Universal Basic Income (UBI) Once this process has been completed, the next step that you would want to undertake is to expand the "Images" that has been displayed when you added a disk image in the previous example, and click on the disk that you've mounted. Project 15: Using ProDiscover Basic Edition (20 Points) The next image displays the settings that you should be utilizing. Once you've selected this option make sure that you select "All Files" for file type and choose the disk image that you've created. Loading an image into ProDiscoverįill out the options below and press "Open. After this point, you must select "Images" from the tree view, and then right-click the file and click on "Add. Once the start screen has been loaded, you can then move onward to pressing on the "Open" button. Once you've downloaded and installed ProDiscover, and of course obtained your disk image through the methods explained simply start ProDiscover and follow the next steps.
In order to obtain a copy of ProDiscover you should visit the following web location: ProDiscover and if you want to follow along to the files that are displayed in explorer and the files that the forensic software sees, you may download PassMark OSFMount.įinally, if you need to procure a forensic image and make sure the image is sound please review this resource: Obtain Disk Image With Linux as it will guide you through the process to forensically obtain a disk image, verify the image and make sure you are not writing to the device itself. The first thing that we will mention is that you will have to download, or order a copy of ProDiscover before you can begin going down this route. Although this is an older version it may in fact be the same in the newer versions - if however, it is not we will attempt to get a newer version of ProDiscover in order to demonstrate the use of the software in another article. The main purpose of this document is for forensic file recovery with ProDiscover.
This article covers information regarding ProDiscover Forensic tools to retrieve files from a computer whose data has been destroyed.