CHAPTER 02 35 MIN READ INTERMEDIATE

Disk and File System Forensics: Imaging, Partitions & Data Recovery

Most investigations start with a disk image. This chapter covers how to acquire one forensically soundly, how partition tables and file systems organize what is on it, and how to recover data that is supposedly gone.

disk imaging NTFS data carving write blockers

Acquisition and Imaging

Acquisition is the process of capturing a copy of storage media that stands in for the original throughout the investigation. It happens two ways: live, against a running system, or dead-box, with the drive removed and imaged offline.

MethodWhen usedTrade-off
Live acquisitionSystem can't be powered off (encryption, uptime requirements, volatile data needed)Captures RAM and running state, but the act of imaging changes the live system slightly
Dead-box acquisitionDrive can be removed and imaged offlineCleanest, most defensible copy, but loses volatile memory and any state that only exists while running

A write blocker, hardware or software, sits between the examiner's system and the original media and physically or logically prevents any write command from reaching it. This is what makes the acquisition forensically sound: the original disk is never modified during imaging.

FormatNotes
Raw / ddBit-for-bit copy of the media, no metadata container, universally supported by forensic tools
E01 (EnCase)Compressed, embeds case metadata and a hash inside the image file itself
AFFOpen format alternative, similar goals to E01 without vendor lock-in
Note: A cryptographic hash (commonly SHA-256) is computed immediately after imaging and compared against a hash of the original media. A match proves the image is an exact, unaltered copy, which is what makes it defensible later.

Partitioning and Boot Structures

Before an examiner looks at any file, they check the partition table. It shows what volumes and file systems exist on the disk, which determines every tool and technique used from that point forward.

PropertyMBRGPT
Max primary partitions4 (or 3 primary + 1 extended holding logical partitions)128 by default
Max disk sizeCapped by its 32-bit sector addressing, around 2 TBNot limited by the same constraint, supports much larger disks
Partition table locationFirst sector of the diskPrimary header near the start of the disk
RedundancyNo backup, a damaged sector 0 can take the whole table with itKeeps a backup header, typically at the end of the disk

A corrupted or unusual partition table is itself a finding worth noting before any deeper analysis begins.

File System Internals

Once the partitions are known, the examiner is working inside a specific file system. Each tracks files differently, and that difference shapes what evidence survives.

PropertyNTFSFAT32exFAT
Primary metadata structure$MFT (Master File Table)FAT tableFAT table (extended)
JournalingYes, via $LogFileNoNo
Typical use todayWindows internal drivesLegacy systems, some embedded devicesRemovable and flash media
Note: Slack space (the unused portion of a cluster past the end of a file's actual data) and unallocated space (clusters not currently assigned to any file) are both forensically significant. Old data can persist in either after a file is deleted or a cluster is only partially overwritten by newer, smaller data.

Deleted File Recovery and Data Carving

Deleting a file normally just removes the file system's pointer or reference to its data. The data itself stays on disk until something else overwrites those clusters, which is why recovery is often possible well after deletion.

  • Metadata-based recovery: the file system record still exists (marked deleted) and still points to the original clusters, so the file can often be restored intact with its name and timestamps.
  • Signature-based carving: unallocated space is scanned for known file header and footer byte patterns, and data between them is reconstructed as a file even with no surviving metadata.
Limitation: Fragmented files, where a file's data is not stored in contiguous clusters, are hard or impossible to carve cleanly, since carving assumes the data between a header and footer belongs to one continuous file.

Practical Disk Examination Workflow

Disk examination is rarely exhaustive from the start. Examiners scale effort to what the investigation actually needs.

1
Triage
Quick look for obvious, relevant artifacts to confirm the disk is worth full examination
→
2
Targeted Examination
Pull specific artifact types tied directly to the investigation's questions
→
3
Full Analysis
Exhaustive review of the image when targeted examination doesn't answer the questions
→
4
Reporting Handoff
Findings documented and handed off with enough detail to be reproduced
Note: The disk image acquired here is what the next two chapters build on directly, Chapter 3 (Windows Artifact Forensics) pulls specific artifacts from it, and Chapter 5 (Timeline Analysis) reconstructs activity across it.

Key Takeaways

  • Write blockers prevent any write to original media, which is what makes an acquisition forensically sound.
  • Raw/dd, E01, and AFF trade off simplicity, compression, and embedded metadata differently.
  • A hash computed after imaging and checked against the original proves the image is an exact copy.
  • GPT supports far larger disks and more partitions than MBR, and keeps a backup header MBR lacks.
  • NTFS, FAT32, and exFAT differ in metadata structure and journaling, which affects what evidence survives.
  • Deletion removes a pointer, not the data, so recovery and carving are possible until overwritten, but fragmentation defeats carving.

Knowledge Check

Click an answer to reveal the explanation.

Why is a write blocker used during disk acquisition?

Correct answer: B. A write blocker physically or logically blocks writes to the original disk, keeping it unmodified so the acquired image remains defensible.

What is a key advantage of GPT over MBR for partitioning?

Correct answer: B. MBR is capped by 32-bit sector addressing and has no backup of its partition table, while GPT supports much larger disks and stores a backup header, typically at the end of the disk.

Why are deleted files often still recoverable?

Correct answer: B. Deletion normally removes the reference to the file's clusters, not the underlying data, so the data persists and can be recovered until it is overwritten.