Digital forensics often involves recovering deleted, hidden, encrypted, or damaged data.
Techniques:
- File carving: Recover files from unallocated space.
- Metadata analysis: Discover creation dates, last access times.
- Password cracking: Unlock encrypted files using brute force or dictionary attacks.
- RAM analysis: Retrieve volatile data such as open files or running processes.
✅ Purpose: Reconstruct evidence that may have been intentionally or unintentionally removed.