Can you view previously copied data?

mike6623

New Member
Member
Messages
149
We have an employee who we believe may have backed up sensitive information to a personal flash drive.

We run Windows 7 professions on 2012 R2 server.

Is there a way that I can check to see what was copied to an external drive? If so, how?
 

My Computer

System One

  • OS
    Windows 8 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    HP Pavilion Elite
    Memory
    16GB
Sector editors like WinHex and HxD will open a disk and let you search the whole thing sector by sector, without regard to file systems. If you want to wipe the drive, flash drives have their own set of considerations. See the paper Schneier linked to here:

https://www.schneier.com/blog/archives/2011/03/erasing_data_fr.html

SSDs with TRIM enabled in effect self-sanitize over time when files are deleted.
 

My Computer

System One

  • OS
    Windows 8.1 Pro with Media Center
Sector editors like WinHex and HxD will open a disk and let you search the whole thing sector by sector, without regard to file systems. If you want to wipe the drive, flash drives have their own set of considerations. See the paper Schneier linked to here:

https://www.schneier.com/blog/archives/2011/03/erasing_data_fr.html

SSDs with TRIM enabled in effect self-sanitize over time when files are deleted.
I appreciate that. I have no experience with this software. Do I simply install and search? Is there something specific I should look for to see what was copied in the last week from HD to external? I am just wanting to see what folders were copied, not necessarily all files.
 

My Computer

System One

  • OS
    Windows 8 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    HP Pavilion Elite
    Memory
    16GB
If you open a disk in file system mode in WinHex, it will show deleted files and folders with dimmed icons beside them containing a question mark. See also undelete programs, which I would assume give you a consolidated list of deleted files/folders to try to restore. You still need to search for contents, though, because it's possible that the file system structures will be overwritten while data from the files remains on the disk.
 

My Computer

System One

  • OS
    Windows 8.1 Pro with Media Center
If you open a disk in file system mode in WinHex, it will show deleted files and folders with dimmed icons beside them containing a question mark. See also undelete programs, which I would assume give you a consolidated list of deleted files/folders to try to restore. You still need to search for contents, though, because it's possible that the file system structures will be overwritten while data from the files remains on the disk.

Thanks, but the info wasn't deleted, it was copied. I am just attempting to find a log that says on this date this folder was copied to this drive. Is it not that in depth, or does it do that as well? Thanks again!
 

My Computer

System One

  • OS
    Windows 8 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    HP Pavilion Elite
    Memory
    16GB
There won't be a log for that, but you could open File Explorer to the root of the drive, enter * as the search term, and perform the search. Explorer will display a flat listing of all the folders and files which you can sort in various ways. You might also want to turn on the display of hidden files before doing this.
 

My Computer

System One

  • OS
    Windows 8.1 Pro with Media Center
There won't be a log for that, but you could open File Explorer to the root of the drive, enter * as the search term, and perform the search. Explorer will display a flat listing of all the folders and files which you can sort in various ways. You might also want to turn on the display of hidden files before doing this.
last question. How do I open File Explorer to the root of the drive? I know how to open it, but not to the root of the drive.
 

My Computer

System One

  • OS
    Windows 8 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    HP Pavilion Elite
    Memory
    16GB
The other way you could try is to view the Last Access Date and Time for files you are concerned about. This facility could be disabled by default though.

You can open to the root just by double-clicking on the C: drive icon in File Explorer
 

My Computer

System One

  • OS
    Windows 8.1 with Bing x64
    Computer type
    Laptop
    System Manufacturer/Model
    Acer Aspire ES1-512-CSYW
    CPU
    Intel Celeron N2840 @ 2.16GHz
    Motherboard
    Acer Aspire ES1-512 BIOS: Insyde Corps V1.07
    Memory
    4GB DDR3L SDRAM
    Graphics Card(s)
    Intel HD
    Internet Speed
    10Mb/s 3 Network HSPA+
    Browser
    IE11 and Firefox
    Antivirus
    Windows Defender
I searched the C drive with * but am not sure how to determine what files had recently been copied to an external device.
 

My Computer

System One

  • OS
    Windows 8 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    HP Pavilion Elite
    Memory
    16GB
The other way you could try is to view the Last Access Date and Time for files you are concerned about. This facility could be disabled by default though.

You can open to the root just by double-clicking on the C: drive icon in File Explorer
that I think would only work if the person opened the files before they copied them to the external device .

to the best of my computer knowledge there is no way of knowing what folders or files the person may have copied to the external device
 

My Computer

System One

  • OS
    win8.1.1 enterprise
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Hinze57
    CPU
    AMD FX 6100 6core 3.30gHz
    Motherboard
    gigibyte ga-78lmy-s2p
    Memory
    4gig ddr3
    Graphics Card(s)
    Radon hd5000 Series
    Sound Card
    onboard realtek hd
    Monitor(s) Displays
    19" viewsonic/ 22"Samsung
    Screen Resolution
    1680x1050
    Hard Drives
    128gig ssd Kingston
    80gig WD 10000 rpm spinner
    Case
    micro
    Keyboard
    microsoft curve 200
    Mouse
    Logitech wireless M215
    Internet Speed
    high speed 20
    Browser
    ie 11
    Antivirus
    windows defender
    Other Info
    updated enterprise apr 2/14
The other way you could try is to view the Last Access Date and Time for files you are concerned about. This facility could be disabled by default though.

You can open to the root just by double-clicking on the C: drive icon in File Explorer
that I think would only work if the person opened the files before they copied them to the external device .

to the best of my computer knowledge there is no way of knowing what folders or files the person may have copied to the external device

The only way I can think of - it's too late here though - is to install a keylogger to capture future attempts.
 

My Computer

System One

  • OS
    Windows 8.1 with Bing x64
    Computer type
    Laptop
    System Manufacturer/Model
    Acer Aspire ES1-512-CSYW
    CPU
    Intel Celeron N2840 @ 2.16GHz
    Motherboard
    Acer Aspire ES1-512 BIOS: Insyde Corps V1.07
    Memory
    4GB DDR3L SDRAM
    Graphics Card(s)
    Intel HD
    Internet Speed
    10Mb/s 3 Network HSPA+
    Browser
    IE11 and Firefox
    Antivirus
    Windows Defender
The Linux Sleuth Kit may tell you.
 

My Computer

System One

  • OS
    Linux Mint 17.2
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba Satellite C850D-st3nx1
    CPU
    AMD E1-1200 APU with Radeon (tm) HD Graphics 1.40 GHZ
    Memory
    12GB
    Graphics Card(s)
    AMD Radeon™ HD 7310 Graphics
    Sound Card
    Realtek HD
    Monitor(s) Displays
    LCD
    Screen Resolution
    1366 x 768
    Hard Drives
    Crucial M500 240GB SSD
    Mouse
    Logitech M525
    Internet Speed
    45/6 - ATT U-Verse
    Browser
    Google Chrome
    Antivirus
    None needed. It is Linux.
    Other Info
    Arris NVG589 Gateway; Router - Cisco RV320; Switch - Netgear GS108 8-Port Switch & Trendnet TEG-S50g 5-Port Switch; Access Points - Engenius ECB350, Trendnet TEW-638APB; NAS - Lenovo ix2-4; Printer - Brother HL-2280DW; Air Print Server - Lantronix XPrintServer

    A/V UPS - Tripp-Lite Smart 1500LCD 1500 Va/900 W.
Thanks, but the info wasn't deleted, it was copied. I am just attempting to find a log that says on this date this folder was copied to this drive. Is it not that in depth, or does it do that as well? Thanks again!
If this is a Domain, the AD logs would tell you if a share was accessed, by what username & the time it was accessed.
 

My Computer

System One

  • OS
    Linux Mint 17.2
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba Satellite C850D-st3nx1
    CPU
    AMD E1-1200 APU with Radeon (tm) HD Graphics 1.40 GHZ
    Memory
    12GB
    Graphics Card(s)
    AMD Radeon™ HD 7310 Graphics
    Sound Card
    Realtek HD
    Monitor(s) Displays
    LCD
    Screen Resolution
    1366 x 768
    Hard Drives
    Crucial M500 240GB SSD
    Mouse
    Logitech M525
    Internet Speed
    45/6 - ATT U-Verse
    Browser
    Google Chrome
    Antivirus
    None needed. It is Linux.
    Other Info
    Arris NVG589 Gateway; Router - Cisco RV320; Switch - Netgear GS108 8-Port Switch & Trendnet TEG-S50g 5-Port Switch; Access Points - Engenius ECB350, Trendnet TEW-638APB; NAS - Lenovo ix2-4; Printer - Brother HL-2280DW; Air Print Server - Lantronix XPrintServer

    A/V UPS - Tripp-Lite Smart 1500LCD 1500 Va/900 W.
Back
Top