Microsoft Switzerland Security Blog

Security informations brought to you by the Swiss Security Team.

Blogs

What happens to the stuff in the Recycle bin?

  • Comments 1
  • Likes

Forensic Analysis of Microsoft Windows Recycle Bin Records

"Contrary to popular belief, when a file is deleted from a computer it is not really deleted. Windows utilizes a repository for deleted files called the Recycle Bin. The existence of the Recycle Bin allows a user to retrieve a document he accidentally deleted. In order for Windows to undelete a file in this manner, certain information must be stored in records so that the original information about the file may be restored, such as the file name..."

http://www.e-fense.com/helix/Docs/Recycler_Bin_Record_Reconstruction.pdf

Very interesting!
-Urs

Comments
  • Yes, very interesting, and in use by quite a number of admins, first responders, and forensic analysts.

Your comment has been posted.   Close
Thank you, your comment requires moderation so it may take a while to appear.   Close
Leave a Comment