De-Wipimization: Unmasking Anti-Forensic Traces with Machine Learning
De-Wipimization: Detection of data wiping traces for investigating NTFS file system
The paper introduces "De-Wipimization," a forensic framework using machine learning and entropy analysis to detect data wiping traces in NTFS file systems. By analyzing NTFS transaction logs (UsnJrnl, LogFile, and MFT), the method achieves over 99% accuracy in identifying specific wiping tools and distinguishes wiped files from normally deleted ones with 96% accuracy.
TL;DR
Data wiping is the ultimate weapon for anti-forensics, designed to make evidence unrecoverable. However, "De-Wipimization" proves that even the most thorough wiping tools leave a "digital footprint" in the low-level transactions of the NTFS file system. By training machine learning models on metadata like the USN Journal, researchers can now identify which files were wiped, which tool was used, and what security standard was applied—with up to 99% accuracy.
The Motivation: When the "Smoking Gun" is Wiped
In a typical investigation, a forensic analyst looks at the Windows Registry or Prefetch files to see if a wiping tool (like CCleaner) was executed. But there is a catch: modern wiping tools are designed to wipe their own tracks.
If a criminal wipes the prefetch files and the registry, the investigator is left in the dark. The authors of this paper realized that while a tool can hide its execution history, it cannot hide the physical behavior it imposes on the file system. Every time a tool overwrites a file seven times (DoD standard), it generates a unique sequence of NTFS transactions that are vastly different from a simple "Right-Click -> Delete" action.
Methodology: The Core of De-Wipimization
The researchers focused on three persistent NTFS sources: MFT (UsnJrnl), and LogFile ($LogFile). Unlike user files, these transaction logs are managed by the kernel and are difficult for standard applications to modify without corrupting the volume.
1. Entropy-Based Partition Detection
Before looking for individual files, the authors use entropy graphs to detect wiped or encrypted partitions.
- Wiped Partitions: Show extremely high entropy (close to 1.0) if filled with random patterns, or extremely low (close to 0) if zeroed out.
- Encrypted Partitions: Look similar to random wiping but often retain a Volume Boot Record (VBR) with specific structural signatures.

2. Feature Engineering: The "Timedelta" Hack
The study's most brilliant insight is the Timedelta feature. Wiping a 1GB file requires overwriting the actual disk sectors multiple times, whereas a normal Windows deletion only marks a record in the MFT as "unused."
- Insight: Wiping actions take significantly more time and generate a massive volume of "Reason Flags" in the UsnJrnl.

Experiments & SOTA Results
The team tested five popular tools: BCWipe, Eraser, Moo0, Sdelete, and CCleaner. They used 11 types of media and document files from the NPS filetypes1 dataset.
Key Results:
- File Wiping Detection: Using a Random Forest model with "All Features," they achieved an accuracy of 96.3% in distinguishing wiped files from normal deletions.
- Tool Identification: Once a wipe was detected, the model identified the specific tool (e.g., Sdelete vs. Eraser) with 100% accuracy in most test cases.
- Sanitization Standard Detection: They successfully grouped tools by how they implement standards like US DoD 5220.22-M and Peter Gutmann (35-pass).

Depth & Insight: Why This Works
The reason Random Forest performs so well here is that wiping tools are essentially state machines. For example, one tool might rename a file to "ZZZZZZ" before deleting it, while another might overwrite the file and then change the timestamp. These "procedural signatures" are captured perfectly by the UsnJrnl transaction sequence.
Limitations
While highly effective on NTFS, the authors note that SSD TRIM commands can complicate the process by re-arranging unallocated space, potentially clearing transaction info. Additionally, the study is currently limited to the Windows environment (NTFS), requiring future adaptation for APFS (macOS) or ext4 (Linux).
Conclusion
"De-Wipimization" proves that in the digital world, perfect deletion is nearly impossible. By analyzing the "shutter speed" of file system transactions rather than just the end state of the data, forensic investigators can bypass anti-forensic barriers and reconstruct the intent and methods of a suspect with mathematical certainty.

