Could "System Volume Information" be used to find out on which system the storage was used?

If one uses a storage device (USB stick or SD card) on Windows, then it leaves "System Volume Information" folder in the file system. Would there be a way so a forensic guy could definitely tell on which computer the storage devi… Continue reading Could "System Volume Information" be used to find out on which system the storage was used?

Are there differences on how storages are formatted between different OS?

If one formats the same USB stick (or SD card) to FAT32 file system on Windows, or on Linux, or on Android – would there be differences so a forensic guy could definitely tell on which OS or even on which specific machine the USB stick was… Continue reading Are there differences on how storages are formatted between different OS?

Is it possible to create an NTFS partition having only the $MFT and $J tables ? Forensics CTF

This is the third part of a forensics challenge in a European CTF, and it is apparently the most difficult one because only three people flagged it among 700 participating.
I’m only here for guidance on what could be done and only want an … Continue reading Is it possible to create an NTFS partition having only the $MFT and $J tables ? Forensics CTF