# Autopsy v4.20.0 - Encryption & File Deletion Query

**URL:** <https://sleuthkit.discourse.group/t/autopsy-v4-20-0-encryption-file-deletion-query/3680>\
**Category:** Autopsy Help\
**Created:** [April 2, 2023, 2:08am UTC](https://sleuthkit.discourse.group/t/autopsy-v4-20-0-encryption-file-deletion-query/3680 "2023-04-02T02:08:28Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarcSG90](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@MarcSG90](https://sleuthkit.discourse.group/u/MarcSG90)\
**Post date:** [April 2, 2023, 2:08am UTC](https://sleuthkit.discourse.group/t/autopsy-v4-20-0-encryption-file-deletion-query/3680/1 "2023-04-02T02:08:29Z")

</div>

Hello All,

I am currently examining an image of a Windows 10 hard drive.  
Is it possible to discover what encryption software was used on the encrypted files?  
and  
What application was used to delete files?  
Furthermore is there other ways to establish methods of obfuscation other than extension mismatches?

Regards,  
Marc
