Anti-forensics is deliberate activity intended to destroy, hide or falsify digital evidence — secure wiping, timestamp manipulation, log deletion, or resetting a device before returning it. The activity almost always leaves its own traces, so the attempt is frequently more probative than what it destroyed.
The paradox that makes it useful evidence
Secure deletion works. A tool that overwrites a file's content several times genuinely destroys it, and no examiner will recover the data.
What it does not destroy is the record that it ran. Installing software leaves registry entries, prefetch and execution artifacts, installer remnants and often an uninstall record. Running it leaves execution timestamps. And the outcome itself is anomalous: a file system with a large region of uniform patterned data, or a document folder whose contents vanished within a four-minute window on the evening before a resignation, does not look like ordinary use.
So the more thoroughly someone destroys the content, the more clearly the destruction stands out. Under Rule 37(e) that distinction is decisive, because intent to deprive unlocks the severe sanctions and negligence does not.
The common techniques and what they leave
Secure wiping utilities. Installation and execution artifacts, licence records, and a characteristic overwrite pattern on disk.
Timestamp manipulation. Changing a file's visible timestamps is straightforward; changing every copy of them is not. File systems maintain more than one set of times, and journals record changes. Inconsistency between them is a reliable indicator.
Log clearing. Clearing an event log is itself a logged event, and the cleared log's own record of being cleared is usually the first thing an examiner looks for.
Factory reset before return. The reset is recorded, and the timing relative to a resignation or preservation notice is usually the point.
Encrypted containers and hidden volumes. These do not destroy anything, they conceal it — and the container's existence, size and access times are visible even when the contents are not.
Physical destruction. Effective on the device, and irrelevant to the backups, cloud copies, and the other party's records.
Distinguishing it from ordinary behaviour
This is where a careful examiner earns their fee, and where an incautious one does real damage. Plenty of innocent activity resembles anti-forensics: disk cleanup utilities run on a schedule, privacy tools clear browsing history by design, corporate IT wipes and reimages machines routinely, and users delete files because they no longer need them.
The finding that holds up is not "a wiping tool was present." It is a pattern: the tool was installed shortly after the preservation duty attached, it ran once, it ran the night before the device was returned, and the deletions coincide with material the person had accessed the previous week. Any one of those alone is weak. Together they are difficult to explain.
An expert who testifies to intent from a single artifact will be dismantled on cross, and deserves to be.
The practical consequence for counsel
If a client has run a wiping tool, find out before the other side does. Disclosed early by your own expert, with an explanation, it is a manageable problem. Discovered by an opposing examiner and presented to a court as concealment, it frequently matters more than the underlying dispute.
From our work
Dealing with anti-forensics in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
