| 
We were contacted by an IT company who had been carrying out some data recovery on a drive where some key files had been lost. It came to light that the user of the machine may have been deleting files with malicious intent after a disagreement with managers.
A forensic examination of the hard drive identified the widespread deletion of directories and files at key times, including out of hours, from the users login profile. Eyewitnesses confirmed that the perpetrator was using the machine at the appropriate times.
Several of the deleted files were password protected and encrypted. CSITechs’ powerful software was able to not only recreate the file but then crack the password. One file was particularly useful in identifying the motivation for the actions of the user.
A full, easy to understand report was compiled and enabled the company to resolve the situation successfully.
|