PRIME MEMBER EXCLUSIVE | 3 Months Free Trial
Auto-renews at INR 199/mo after 3 months. Cancel anytime. Offer ends 15 July, 2026.
Course 36 - Windows Forensics and Tools | Episode 10: Decoding Metadata and File Internals
Failed to add items
Sorry, we are unable to add the item because your shopping basket is already at capacity.
Add to cart failed.
Please try again later
Add to wishlist failed.
Please try again later
Remove from wishlist failed.
Please try again later
Follow podcast failed
Unfollow podcast failed
-
Narrated by:
-
Written by:
- Deleting a file in Windows does not immediately erase it
- Instead, Windows:
- Moves it to a hidden system structure
- Renames it
- Keeps both metadata and data intact
- The Recycle Bin is often a hidden evidence repository
- Deleted files usually remain:
- On disk (physically intact)
- With modified references only
- Investigators can often recover:
- Files
- Paths
- Deletion timestamps
- INFO2 file
- Stored inside:
- Recycler folder
- Original file path
- File size
- Deletion order
- Acts as an index of deleted files
- $Recycle.Bin
- $R file
- Contains actual file data
- $I file
- Contains metadata:
- Original name
- Path
- Deletion timestamp
- Contains metadata:
- Data and metadata are split for tracking integrity
- $I file headers contain version indicators:
- 01 → older Windows versions
- 02 → Windows 10 era
- Helps investigators determine:
- Operating system version
- Timeline of deletion activity
- Hex editors
- Forensic analysis tools
- File paths
- Deletion timestamps
- File size metadata
- Original filenames
- Even “deleted” files can be reconstructed byte-by-byte
- Access $Recycle.Bin
- Match $R and $I files
- Decode metadata
- Reconstruct original file structure
- Extract evidence
- Deleted documents
- Malware payloads
- Sensitive user files
- Evidence of file wiping attempts
- Attackers often forget the Recycle Bin still holds traces
- Recycle Bin does not permanently delete data immediately
- Legacy systems use INFO2 index files
- Modern systems use $R and $I file pairs
- Metadata and file content are separated
- Hex analysis allows full reconstruction of deleted activity
- Delete action → Recycle Bin redirect → hidden storage → forensic recovery
You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy
adbl_web_anon_alc_button_suppression_t1
No reviews yet