Hello All,
I am currently examining an image of a Windows 10 hard drive.
Is it possible to discover what encryption software was used on the encrypted files?
and
What application was used to delete files?
Furthermore is there other ways to establish methods of obfuscation other than extension mismatches?
Regards,
Marc