Interesting article about forensics, but reading between the lines, I’m curious about the “encrypted filesystem” comments made. Could it be that EFS is throwing these investigators off the scent? If so, maybe it’s time for a white-paper about how to get around EFS in a forensics context?





