NorthDallas40
Displaced Hillbilly
- Joined
- Oct 3, 2014
- Messages
- 59,162
- Likes
- 86,358
I loved XP. What "forensic"data was destroyed? Access logs intact, Data intact, so what is this "native forensic information" you think was destroyed?
Read the very first link I put up about File slack, RAM slack, and drive slack. Transferring an NTFS image to a FAT32 backup should destroy all of the EOF slack garbage data for starters but Im sure it mangles long file names also. The dreaded ~ truncated file names for example. Normally who cares. But if its for forensics thats critical.
The tweet implied they changed file systems on the image. I have no idea if they did or not. But if they really did go from NTFS to FAT32 drive image integrity really wasnt high on their list.
Either way its late and Im done.
