User Tools

Site Tools


start

Anti-Forensics.com

Digital forensics, anti-forensics detection, artifact interpretation, recovery limits, timeline analysis, and report discipline.

Dead files do not testify. Bad reports do.

Anti-Forensics.com is a defensive technical reference for understanding how digital evidence appears, disappears, survives, misleads, and gets overclaimed by people who should know better. This wiki focuses on anti-forensic indicators, forensic artifacts, storage behavior, timeline reconstruction, evidence preservation, and the ugly little gap between what a trace shows and what someone wants it to prove.

This is not a guide for hiding, destroying, altering, or tampering with evidence. It is a reference for analysts, investigators, incident responders, students, and technically curious readers who want to understand anti-forensics without turning the server into a shovel rack.

Main Index

Start Here

For new readers, begin with the foundation pages before wandering into the basement with the deleted files.

What This Wiki Covers

Anti-forensics is often treated like a dramatic dark art. In real cases, it is usually less theatrical and more irritating: wiped remnants, log gaps, misleading timestamps, recovery failure, cloud sync weirdness, cleanup utilities, encryption, privacy tools, missing metadata, and examiners staring at unallocated space like it owes them a confession.

This wiki is organized around practical forensic questions:

  • What was actually observed?
  • What can this artifact support?
  • What can it not prove by itself?
  • What normal system behavior could explain it?
  • What other evidence should be compared?
  • How should this be written without turning the report into a loaded weapon?

The goal is not to make every artifact look guilty. The goal is to stop bad conclusions from crawling out of the evidence locker wearing a little expert-witness hat.

Topic Why It Matters
Secure Deletion A missing file may matter, but failed recovery is not a confession. Sometimes the file was wiped. Sometimes the SSD did what SSDs do.
Recovery Failure Recovery failure can be meaningful, boring, suspicious, or all three while wearing the same coat.
File Carving Useful for recovery, dangerous when treated like full context. A carved fragment does not arrive with a signed statement.
SSD TRIM TRIM can make deleted data unrecoverable without anyone performing ceremonial evidence burial.
Unallocated Space The graveyard of deleted data, half-truths, fragments, and examiner overconfidence.
Timestamp Manipulation Timestamps can lie, drift, inherit, normalize, or get changed. Treat them like witnesses with alibis and bad shoes.
Windows Prefetch Useful execution evidence, but not proof that a specific human knowingly performed the action.
Shellbags Folder interaction artifacts are useful, but they still need context before being dragged into court.
Artifact Corroboration One artifact makes a suggestion. Independent artifacts make a case. Sometimes. If they behave.
Intent Analysis Limits Intent is not carved out of unallocated space with a spoon. It needs context, corroboration, and restraint.

Anti-Forensics Detection

Digital Forensics Foundations

File Systems and Storage Artifacts

Windows Artifacts

Logs and Timelines

Browser, Mobile, and Cloud Artifacts

Linux and macOS Artifacts

Memory, Malware, and Incident Response

Forensic Checklists

Tools and Resources

Tools parse evidence. They do not create conclusions. A parser can surface an artifact; it cannot stop a bad interpretation from putting on a suit and walking into a report.

Defensive Use Only

This wiki discusses anti-forensics from a defensive, investigative, and educational perspective.

It is intended to help readers:

  • recognize suspicious or misleading evidence patterns
  • understand recovery and storage limits
  • avoid overclaiming user intent
  • write cleaner forensic reports
  • compare artifacts responsibly
  • understand what tools can and cannot prove
  • distinguish technical limits from hostile behavior

Do not use this material to destroy, conceal, alter, or tamper with evidence. That is not advanced tradecraft. That is leaving fingerprints on the shovel.

Reader Takeaway

Anti-forensics is not only about wiping files or hiding traces. In real forensic work, the harder problem is interpretation.

A missing file may matter. A suspicious timestamp may matter. A cleanup tool may matter. But evidence does not become stronger because the paragraph sounds confident.

The clean analyst asks:

  • What was actually observed?
  • What else could explain it?
  • What independent evidence supports it?
  • What cannot be proven from this artifact alone?
  • How should this be written so it survives review?

That is where forensic work becomes useful. Everything else is just unallocated space looking dramatic.

Use Notes

This wiki is for defensive education and technical reference. It should not be treated as legal, forensic, investigative, compliance, or operational advice without qualified professional judgment.

Anti-Forensics.com does not provide instructions for evidence destruction, concealment, tampering, evasion, or misuse. The focus is artifact interpretation, defensive detection, recovery limits, and responsible reporting.

start.txt · Last modified: by maxmin