Abstract:
In a method for recovering a partition using backup boot record information, an unallocated area is separated from a disk or an evidence image. The unallocated area is searched for a location of a backup boot record. Whether is backup boot record of a file system to be detected is present in found sectors is analyzed. If the backup boot record is found to be the backup boot record of the file system desired to be detected as a result of the analysis, it is verified whether the backup boot record is a boot record of a valid partition. If it is verified that the backup boot record is the boot record of the valid partition, a file system of a deleted partition is parsed using the backup boot record and a deleted directory or file is recovered.
Abstract:
Disclosed herein are an evidence collection guidance method and apparatus for file selection. The evidence collection guidance method includes generating pieces of preliminary analysis information that are pieces of collection target information, setting levels of the pieces of preliminary analysis information based on predefined rules, and generating and outputting notification information including summary description information and follow-up measure items related to the pieces of preliminary analysis information corresponding to the levels.