> For the complete documentation index, see [llms.txt](https://zach-wong.gitbook.io/easy-reads/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://zach-wong.gitbook.io/easy-reads/ictf-2024-writeups/undelete.md).

# UnDelete

**Challenge Name: UnDelete**&#x20;

**Category: Forensics**&#x20;

**Difficulty: Medium**&#x20;

**Description: When was the suspicious file deleted? Flag format: MM/DD/2004 12:00:00 UTC**

<figure><img src="https://3959829653-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKsbQ7f9jhHpgfkJbVM1s%2Fuploads%2FlDzXjeMzBsCWXpSqPPLW%2Fimage.png?alt=media&amp;token=5223a636-9f35-4a1f-b716-57c4fcc4181e" alt=""><figcaption></figcaption></figure>

The challenge provided an `.ad1` file to us. The "a" and "d" means Access Data. A quick look up of Access Data reveals that they have a product called FTK Imager which is used to image hard drives and read image data, which is what the file given to us is. So let's open it up there!

<figure><img src="https://3959829653-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKsbQ7f9jhHpgfkJbVM1s%2Fuploads%2FgiopJeaDyPVLPv4crQhp%2Fimage.png?alt=media&amp;token=b4facac2-0c06-4917-bc3c-6a15356019d8" alt=""><figcaption></figcaption></figure>

So once you loaded FTK Imager, click on the icon shown to `Add Evidence Item`.

<figure><img src="https://3959829653-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKsbQ7f9jhHpgfkJbVM1s%2Fuploads%2Fl4lZTaY7j0IQK75vA8vJ%2Fimage.png?alt=media&amp;token=37cd3e0d-b092-4b4e-bbd4-dd0f4c69c3b0" alt=""><figcaption></figcaption></figure>

Click on `Image File`.

<figure><img src="https://3959829653-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKsbQ7f9jhHpgfkJbVM1s%2Fuploads%2FvFsc1xXCONh2eRiSTsar%2Fimage.png?alt=media&amp;token=e7f53970-21ee-4c36-aeed-8a8a9f8d0225" alt=""><figcaption></figcaption></figure>

Now locate the file provided to us and select it as our data source.&#x20;

<figure><img src="https://3959829653-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKsbQ7f9jhHpgfkJbVM1s%2Fuploads%2FQlV99LtlVRQNVeIIt9C7%2Fimage.png?alt=media&amp;token=8b219b00-0e61-4ffa-a0c4-29663d6ee3b1" alt=""><figcaption></figcaption></figure>

Looking at the `Evidence Tree`, we can actually expand the folders. Now within the `root` directory contains a `$Recycle Bin` folder, this folder is where your recycle bin items are! Within that folder contains a weird ID, this ID is called a SID or Security Identifier. Basically, it is your user's ID within a Windows computer.&#x20;

<figure><img src="https://3959829653-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKsbQ7f9jhHpgfkJbVM1s%2Fuploads%2FASvqjKLuOHI5XTfKJQhp%2Fimage.png?alt=media&amp;token=7a1d30d2-37de-440a-8768-81252fdbc481" alt=""><figcaption></figcaption></figure>

Clicking on that folder and looking at the contents, reveals a couple of files one of which asks us, "When was I deleted?" a hint that the timestamp of which this file is deleted is the flag. Looking at the modified date at the side which describes when the file was modified in any way including deletion shows us that the file was deleted on `04/14/2024 10:47:45 AM` which is already in UTC timing as FTK Imager will automatically convert the timing to UTC timing.&#x20;

```
Flag: ICTF24{04/14/2024 10:47:45 AM}
```
