by Alt » Fri May 21, 2021 10:46 am
Based on the R-Studio screenshot provided in the referenced document, we assume that:
1. R-Studio scanned and analyzed an image of a certain storage device (object), but we cannot assert with any certainty that the image corresponds to the original state of that storage device since it wasn't done in our lab.
2. We also cannot determine a type of the original object, as it could be a RAID, a single physical disk, or a virtual device.
3. R-Studio marks files as "deleted" on a volume if the operating system doesn't show these files when it opens the volume through the standard file enumeration procedures. The reason for this could be one of the following:
* The files are marked as "deleted" by the operating system.
* The files are not marked as "deleted" by the operating system but their parent folders were marked as "deleted".
* The files have been found by using R-Studio's additional methods of object data analysis such as, for example, analysis of the $LogFile file or analysis of extra found MFT extents.
4. As explained above, we cannot determine whether the original object was a RAID or not, but usually files from an incorrectly assembled RAID cannot be recovered with correct content, especially when the files are large.
Based on the R-Studio screenshot provided in the referenced document, we assume that:
1. R-Studio scanned and analyzed an image of a certain storage device (object), but we cannot assert with any certainty that the image corresponds to the original state of that storage device since it wasn't done in our lab.
2. We also cannot determine a type of the original object, as it could be a RAID, a single physical disk, or a virtual device.
3. R-Studio marks files as "deleted" on a volume if the operating system doesn't show these files when it opens the volume through the standard file enumeration procedures. The reason for this could be one of the following:
* The files are marked as "deleted" by the operating system.
* The files are not marked as "deleted" by the operating system but their parent folders were marked as "deleted".
* The files have been found by using R-Studio's additional methods of object data analysis such as, for example, analysis of the $LogFile file or analysis of extra found MFT extents.
4. As explained above, we cannot determine whether the original object was a RAID or not, but usually files from an incorrectly assembled RAID cannot be recovered with correct content, especially when the files are large.