HDD Data Recovery in Digital Forensics – Lesson 1
In these training sessions we’ll discover how a Hard Drive works physically and logically. This information is not easily available on the internet but is vital in order to understand how to diagnose or even understand if a drive was tampered to prevent access to the data area
Topics:
HDDs are an example of mechatronics, where electronics and mechanics are fused together. Understanding how the interfacing of mechanics by electronics works allows us to understand the possible causes of data loss, as well as possible anti-forensics techniques to prevent a forensic investigationWe will start by dividing the HDD into 2 main parts:
- Hard Drive Parts and Functions
- Electronic Board
- Mechanical Parts
- Magnetic Heads Positioning System
- How are Bits Stored
- Magnetic Recording Methods
- HDA – Head Disk Assembly
- PCBA – Printed Circuit Board Assembly
PCBA:
Is the mainboard, its aim is to make the drive load its own firmware and communicate with the PC through a controllerMain components
- MCU
- ROM
- SPINDLE CONTROLLER
- BUFFER
- PCBA: EMBEDDED VS EXTERNAL ROM
- [1] Western digital laptop drive embedded rom
- [2] Western digital laptop drive external rom
Inside a ROM chip we can find
- Code
- Modules
- Adaptive data
- Head map
- Boot flags
- Techno overlay modules
- Modules directories
- Is ROM worthy to analyze?
- Which kind of data can be stored?
- Should ROM be tampered with?
- Is ROM somehow hashed in standard forensic acquisition?
Includes the external case with all the magnetic and mechanical parts
- SPINDLE MOTOR
- AIR FILTER
- HEAD STACK
- BOTTOM MAGNET
- TOP MAGNET
- SPACERS
- HEAD RAMP
Includes the external case with all the magnetic and mechanical parts
- R/W heads
- Preamp chip
- Head sliders
- Head stack connector
- VCM Voice Coil Motor
Read element and write element
- Load/unload tip
- Reader/writer/heater connectors
- Read/write element
- Air bearing contour
- Micro actuator
- Air is needed to let the heads “fly” over the platters
- Air must be filtered
- To open an HDD we need to work in a clean environment, such as a flow laminar clean bench.
- We normally use an ISO5 flow hood.
CONTAMINATION VS FLIGHT HEIGHT
- FINGER PRINT .00062 in.
- DUST PARTICLE .0015 in.
- HUMAN HAIR .003
Positioning system : Head map
Downloadable Materials: