With the assistance of a computer forensics examiner, the header information was obtained, which included the date stamp and the video header. I proceeded to perform the forensics analysis with this valuable information. Initially, I carved the data manually. This meant that I had to hold down the Shift and Page Down keys to highlight two-megabyte segments of data, one at a time, and then export it out to a folder located on another forensic hard drive. This process sounds easy - but it wasn’t, because a video clip is a huge file. I did this for 2 weeks. Trust me, it quickly became tedious, and eventually painful.
After two weeks of this, I used the software that would repair the recovered data files (that is, convert it back into the original video). This was the highlight of all the work, and the results were seemingly worth the wait: “Hey, I can see some video!” That was a good feeling.
This continued for another week, and the good feelings faded. There had to be a better way. I then tried one of the validated forensic tools that we have in the laboratory, one that would “automatically” carve out the data for me. The results were astonishing - and disappointing. The tool quickly created 49 folders, each containing 400 carved data files. No more holding down the Shift and Page Down keys! But then, the repair tool was unable to do anything with the carved files. So I used a different carving tool - same results. The tools seemed to do what they were supposed to do, but the repair software couldn’t do anything with the data.
I continued carving manually for two months. And after all this time, I was amazed to find that I had recovered only a few seconds of video.
The moral of this article is sometimes the technology fails, and the conventional way is the only way that will work, even though it may take you an extraordinary amount of time to get to the final result.