{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 36 - Windows Forensics and Tools | Episode 10: Decoding Metadata and File Internals","slug":"course-36-windows-forensics-and-tools-episode-10-decoding-metadata-and-file-internals","published_at":"2026-06-08T06:00:02+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-10-decoding-metadata-and-file-internals","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-36-windows-forensics-and-tools-episode-10-decoding-metadata-and-file-internals--72013766","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72013766/forensic_internals_of_the_windows_recycle_bin.mp3","summary":"In this lesson, you’ll learn about: Windows Recycle Bin forensics and deleted file recovery1. Why the Recycle Bin Matters in Forensics Deleting a file in Windows does not immediately erase it Instead, Windows: Moves it to a hidden system structure Renames it Keeps both metadata and data intact 🔹 Key Idea The Recycle Bin is often a hidden evidence repository 2. Core Forensic Insight Deleted files usually remain: On disk (physically intact) With modified references only 👉 Result: Investigators can often recover: Files Paths Deletion timestamps 3. Legacy Windows Recycle Bin (Windows XP and earlier)🔹 Structure Used INFO2 file Stored inside: Recycler folder 🔹 What it contains Original file path File size Deletion order 👉 Key Insight: Acts as an index of deleted files 4. Modern Windows Recycle Bin (Vista → Windows 10)🔹 Structure Used $Recycle.Bin 🔹 File Pair SystemEach deleted file creates two entries: $R file Contains actual file data $I file Contains metadata: Original name Path Deletion timestamp 👉 Key Insight: Data and metadata are split for tracking integrity 5. Windows 10 Forensic Markers🔹 Version Identification $I file headers contain version indicators: 01 → older Windows versions 02 → Windows 10 era 🔹 Why it matters Helps investigators determine: Operating system version Timeline of deletion activity 6. Hex-Level Analysis🔹 Tools used Hex editors Forensic analysis tools 🔹 What investigators extract File paths Deletion timestamps File size metadata Original filenames 👉 Key Insight: Even “deleted” files can be reconstructed byte-by-byte 7. Forensic Workflow🔹 Step-by-step process Access $Recycle.Bin Match $R and $I files Decode metadata Reconstruct original file structure Extract evidence 8. Investigative Value🔹 What can be recovered Deleted documents Malware payloads S…","meta_description":"In this lesson, you’ll learn about: Windows Recycle Bin forensics and deleted file recovery1. Why the Recycle Bin Matters in Forensics Deleting a file in…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1348,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-36-windows-forensics-and-tools-episode-10-decoding-metadata-and-file-internals/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-10-decoding-metadata-and-file-internals.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}