Anti-Forensics tools and script to securely remove or destroy file in a directory using sdelete
Use only in windows machine , i will gather information about securely remove files in linux or macOs soon
Case Study:
I use it in the event of a Computer Assisted Test, where the exam mainly stores the questions and answers in a digital drive. So, we must ensure that the file cannot be recovered and analyzed
![screen-shot-2023-05-14-at-7 13 53-pm](https://private-user-images.githubusercontent.com/139729508/255093775-56c9c8ed-d283-4251-9380-189fae893fe0.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzg5MTk2OTAsIm5iZiI6MTczODkxOTM5MCwicGF0aCI6Ii8xMzk3Mjk1MDgvMjU1MDkzNzc1LTU2YzljOGVkLWQyODMtNDI1MS05MzgwLTE4OWZhZTg5M2ZlMC5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjA3JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIwN1QwOTA5NTBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1mOTAzMWQ4YzlmYTBiNGU0ZTJhMDE2NTY2M2QwN2UyMWYzNzFhNzFiMjdmNDIzNWQ5Y2U3NTMyMjY2ZmQxOTQ4JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.Zz-Ik2OmzKfawaGVooSrK9Eb4sjuZCqQ1A-O31BMs5Y)
anti-digital forensics refers to the use of techniques, tools, or practices by individuals or entities to hinder, disrupt, or evade digital forensic investigations. The goal of anti-digital forensics is to make it difficult or even impossible for forensic investigators to recover and analyze digital evidence.
sdelete
SDelete (Secure Delete) is a command-line utility developed by Microsoft that securely deletes files and cleans free space on Windows systems. It is part of the Sysinternals Suite, a collection of useful tools for Windows administration and troubleshooting, created by Mark Russinovich and Bryce Cogswell.
How to Use:
- Download the two required files:
sanitize-file.bat
andsdelete.exe
. - Move the two files to the flash disk or directory that needs to be cleansed.
- Open the command terminal and run
sanitize-file.bat
. - Enter the directory path that needs to be cleaned in the command line.
- Press
Enter
to start the cleansing process in 4 phases. - Once the process is complete, the files will be deleted completely.
Important Considerations:
- Securely removing a file is irreversible, and the data cannot be recovered once overwritten.
- Be cautious when using these commands, as they permanently delete data. Always make sure you genuinely want to delete the file before proceeding.
- Ensure you have the necessary permissions to delete the file.
- For even greater security, consider encrypting sensitive files before storage, so even if they are recovered, they remain unreadable without the decryption key.