3. Sceneario
• Format SDCard for testing (full format / fill zero)
1
• Copy evidence file(s) to external & internal memory card
2
• Get images from external & internal memory with USB Image Tools & dd command
2
• Delete the evidence file(s) (in this case as .JPEG image) with local application (ES Explorer)
3
• Get images (again) from external & internal memory with USB Image Tools & dd command
4
• Extract all kind of files from both images with Files Scavenger.
5
• Compares extracted and founded evidences with real file(s) with JPEGNoob
6
• If the same, then recovery process is successfull
7
6. Data Preservation
Creating External Memory’s Image Files:
1. Enable USB Mode
2. Create Images with USB Image Tool
3. [Optional] Can use md5 checking
7. Analysis
• Use File Scavenger to acquire all
(deleted + hidden) data
• Find ‘likely’ successfull recovered
digital picture (cause sometimes
the recovered image/picture has
different name).
• Compare real image and
recovered image with
JPEGSnoop (For JPEG)
10. Conclusion
• Recovering data in internal memory card was very hard to do
especially if the memory size is small, because usually it will
automatically ‘fully deleted’
• In External Memory, deleting files doesn’t delete the real files.
The deleted files still resident the memory in, often in the
same path.