Volume Shadow Copies
Also called VSS, shadow copies, previous versions, System Restore points.
- PLATFORM
- Windows
- CATEGORY
- Deletion and Recovery
- INDEX
- 23 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
Point-in-time block-level snapshots of a volume, often holding an earlier version of a file that has since been altered or deleted — sometimes the only copy of a document as it originally stood.
Where it lives
Shadow copy storage on the protected volume, exposed as device paths under \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of volume shadow copies” is neither.
What it records
The shadow copy service preserves blocks that are about to change, so that the volume can be presented as it stood when the snapshot was taken. Snapshots are created by system protection, by backup software, and by some installers. The storage area is size-limited, and when it fills the oldest snapshots are deleted to make room — so the set of available copies is a function of volume activity, not of a schedule.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- The content of a file as it stood at a specific earlier moment, which is the strongest evidence available that a document was later altered
- That a file existed on a date, even where it has since been deleted and its data overwritten in the live volume
- The state of registry hives and event logs at an earlier point, giving a second, older copy of artifacts that have since rolled over
- That a directory structure existed as described, at snapshot time
- Differences between successive snapshots, which can date a change to a window
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- Who made a change between two snapshots. A shadow copy is a state, not a log; it shows what differed and never who differed it
- When, within the interval between two snapshots, the change happened. The window is as wide as the gap between them
- That a snapshot existed for the date that matters. System protection is disabled by default for non-system volumes and may be off entirely, and old snapshots are deleted automatically when the storage area fills
- That deleting shadow copies was concealment. They are deleted automatically as a matter of routine, and administrative tools remove them for ordinary maintenance reasons
- A continuous history. Snapshots are discrete points, frequently sparse, and the gaps between them are where most disputed activity sits
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Establishing that the storage area's size limit, not any human act, removed the snapshots the examiner wishes existed
- Widening the interval between snapshots to show the change cannot be dated closely enough to matter
- Arguing that a document recovered from a snapshot is a draft rather than an operative version
- Showing that snapshot deletion was performed by maintenance tooling or by a disk-space condition rather than deliberately
What survives, and for how long
Snapshots persist until the shadow storage area fills, at which point the oldest are deleted automatically — so coverage is measured by volume activity rather than by time. They do not survive reformatting or imaging tools that copy only allocated live data, which is one reason full physical acquisition matters.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Can a volume shadow copy prove a document was altered?
It can prove what the document contained at the moment the snapshot was taken, which is usually the strongest available evidence that a later version differs. What it cannot do is identify who changed it or when within the interval — a shadow copy is a preserved state, not a log of edits, so the change can only be placed somewhere between two snapshots.
Why are there no shadow copies on this computer?
Commonly because system protection is off — it is disabled by default for non-system volumes and can be disabled entirely — or because the shadow storage area filled and the oldest snapshots were deleted automatically to make room. Deletion of shadow copies is therefore routine and not, on its own, evidence of concealment. What matters is whether anything unusual coincided with it.
Do shadow copies contain old registry and event log data?
Yes, and this is often their most valuable use. A snapshot preserves the volume as it stood, including registry hives and event logs, so it can supply an older copy of an artifact that has since rolled over or been overwritten in the live system. A capped log that no longer covers the relevant period may still cover it inside a snapshot.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
$MFT (Master File Table)
The NTFS index of every file and directory on a volume, holding two independent sets of four timestamps per file plus, for small files, the file's entire content.
Recycle Bin ($I and $R Files)
Deleted files moved to the Recycle Bin are stored as a renamed copy of the content plus a metadata file recording the original path, original size and the deletion time.
$UsnJrnl (USN Change Journal)
A per-volume journal recording every change to every file — creation, deletion, rename, data overwrite — with a timestamp, a filename and a reason code for each entry.
Windows Search Index and WordWheelQuery
The desktop search database indexes file properties and, for many file types, full text — so it can retain the content of documents that were deleted before the index was rebuilt.
Whether the volume shadow copiesevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.