How to perform a forensic PC investigation

forensic search
Using this tool, you can see if anyone's using your PC for nefarious purposes

When you have a technical interest in Windows or PCs in general, there are few things as fascinating as a good computer forensics package.

This is partly because they're an excellent way to check exactly how someone is using a computer – the files they're accessing, the websites they're viewing and any information they may be trying to hide. It's a little sneaky, but if you have suspicions that, for example, an employee is doing something they shouldn't on a work PC, then this could prove very useful.

Click the 'Create index' tab, for instance, and you'll be able to choose a start folder that defines the file structure you'd like to search. Any subfolders will be included automatically, so to search the entire C: drive, you would simply specify 'C:\'.

It may take a very long time to index the whole drive, so if you only want to search for something in the Documents folder, browse to 'C:\Users\[Name]\My Documents' instead.

forensic search

SEE HERE: Thumbnail previews are available in searches, making it easy to find anyimages you need, such as photos you've deleted and want to restore

The indexing is tool is already comprehensive, but you can make it even more so with a few extra tweaks. Click 'Config', then select both 'Scan files with no extensions' and 'Scan files with unknown extensions' to try to uncover content that other tools might miss. Then choose 'Files and unallocated sectors' to look for content in files that may have been deleted.

When you've finished, click 'Create index', then leave the program for a while. It will have to scan a huge number of files and the process will therefore take some time to complete.

It's worth the effort though, because when it's finished, you can use the 'Search index' tab to enter your key words and pull up matching files, images, emails and more almost immediately, including content that wouldn't necessarily be available if you used Windows search alone.