Anti-Forensics Techniques Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Anti-Forensics Techniques flashcards as text
How can a forensic investigator detect timestomping on a Windows NTFS volume?
Answer: By comparing $MFT timestamps against $LogFile and $UsnJrnl entries for inconsistencies
Investigators can detect timestomping by comparing timestamps recorded in the $MFT with those in the $LogFile and $UsnJrnl change journal, which may show discrepancies when MAC times have been manipulated.
What is 'file system tunneling' as exploited in anti-forensics on Windows?
Answer: A Windows OS behavior that preserves original timestamps when a file is deleted and recreated with the same name within a short window
File system tunneling is a Windows feature that preserves original creation timestamps when a file is deleted and a new file with the same name is created within roughly 15 seconds, which attackers can exploit to maintain falsely consistent timestamps.
Which forensic recovery method is specifically used to recover files subjected to anti-forensic deletion by searching for file headers and footers in raw disk data?
Answer: File carving (data carving)
File carving recovers files by scanning raw disk data for known file headers and footers, bypassing file system structures that may have been manipulated, deleted, or corrupted.
What is the goal of 'artifact wiping' as an anti-forensics technique?
Answer: To remove all forensic traces of a tool's presence including registry entries, prefetch files, and log entries
Artifact wiping aims to remove all traces of a tool's execution, including registry keys, prefetch files, event logs, and temp files, preventing investigators from determining which tools were run on the system.
What disk regions, not normally reported by the OS, can be used to hide data as an advanced anti-forensics technique?
Answer: Host Protected Area (HPA) and Device Configuration Overlay (DCO)
The Host Protected Area (HPA) and Device Configuration Overlay (DCO) are disk regions invisible to the operating system and most forensic tools by default, making them useful for hiding data from investigators.
Which technique allows an attacker to hide malicious code inside a legitimate-looking program so it bypasses casual inspection?
Answer: Trojan horse embedding
Trojan horse embedding conceals malicious code within a legitimate-appearing program, making it difficult for casual inspection or signature-based tools to detect the hidden payload.
What does 'counter-forensics' refer to from a forensic investigator's perspective?
Answer: Investigator techniques and tools used to detect, overcome, and document anti-forensic measures
Counter-forensics refers to the investigator's use of techniques and specialized tools to detect, overcome, and formally document anti-forensic measures employed by suspects to preserve evidence integrity.