Digital forensics, anti-forensics detection, artifact interpretation, recovery limits, timeline analysis, and report discipline.
Dead files do not testify. Bad reports do.
Anti-Forensics.com is a defensive technical reference for understanding how digital evidence appears, disappears, survives, misleads, and gets overclaimed by people who should know better. This wiki focuses on anti-forensic indicators, forensic artifacts, storage behavior, timeline reconstruction, evidence preservation, and the ugly little gap between what a trace shows and what someone wants it to prove.
This is not a guide for hiding, destroying, altering, or tampering with evidence. It is a reference for analysts, investigators, incident responders, students, and technically curious readers who want to understand anti-forensics without turning the server into a shovel rack.
For new readers, begin with the foundation pages before wandering into the basement with the deleted files.
Anti-forensics is often treated like a dramatic dark art. In real cases, it is usually less theatrical and more irritating: wiped remnants, log gaps, misleading timestamps, recovery failure, cloud sync weirdness, cleanup utilities, encryption, privacy tools, missing metadata, and examiners staring at unallocated space like it owes them a confession.
This wiki is organized around practical forensic questions:
The goal is not to make every artifact look guilty. The goal is to stop bad conclusions from crawling out of the evidence locker wearing a little expert-witness hat.
| Topic | Why It Matters |
|---|---|
| Secure Deletion | A missing file may matter, but failed recovery is not a confession. Sometimes the file was wiped. Sometimes the SSD did what SSDs do. |
| Recovery Failure | Recovery failure can be meaningful, boring, suspicious, or all three while wearing the same coat. |
| File Carving | Useful for recovery, dangerous when treated like full context. A carved fragment does not arrive with a signed statement. |
| SSD TRIM | TRIM can make deleted data unrecoverable without anyone performing ceremonial evidence burial. |
| Unallocated Space | The graveyard of deleted data, half-truths, fragments, and examiner overconfidence. |
| Timestamp Manipulation | Timestamps can lie, drift, inherit, normalize, or get changed. Treat them like witnesses with alibis and bad shoes. |
| Windows Prefetch | Useful execution evidence, but not proof that a specific human knowingly performed the action. |
| Shellbags | Folder interaction artifacts are useful, but they still need context before being dragged into court. |
| Artifact Corroboration | One artifact makes a suggestion. Independent artifacts make a case. Sometimes. If they behave. |
| Intent Analysis Limits | Intent is not carved out of unallocated space with a spoon. It needs context, corroboration, and restraint. |
Tools parse evidence. They do not create conclusions. A parser can surface an artifact; it cannot stop a bad interpretation from putting on a suit and walking into a report.
This wiki discusses anti-forensics from a defensive, investigative, and educational perspective.
It is intended to help readers:
Do not use this material to destroy, conceal, alter, or tamper with evidence. That is not advanced tradecraft. That is leaving fingerprints on the shovel.
Anti-forensics is not only about wiping files or hiding traces. In real forensic work, the harder problem is interpretation.
A missing file may matter. A suspicious timestamp may matter. A cleanup tool may matter. But evidence does not become stronger because the paragraph sounds confident.
The clean analyst asks:
That is where forensic work becomes useful. Everything else is just unallocated space looking dramatic.
This wiki is for defensive education and technical reference. It should not be treated as legal, forensic, investigative, compliance, or operational advice without qualified professional judgment.
Anti-Forensics.com does not provide instructions for evidence destruction, concealment, tampering, evasion, or misuse. The focus is artifact interpretation, defensive detection, recovery limits, and responsible reporting.