Hi I’ve started at forensic analysis and I have some doubts. Could anyone help.
1 - Once the analysis has been performed and deleted files have been recovered, is there any way to recover the content of those files? A forensic analysis has been performed with Autopsy on a piece of evidence and the software recovers deleted files (png, xlsl, pdf) but cannot display their content. Is it possible to see the content of the png, pdf, …, before they were deleted? How?
2- Is it possible to break devices encryption to be able to analyse evidence? Let’s say you don’t have the password that encrypted it. How?