Research: source-drive preservation

What Windows wrote to a Tesla USB drive in our recovery tests

Our Windows USB recovery tests: observed writes, a real SanDisk drive, software offline/online simulation, and the limits of unverified protection.

The finding

Windows wrote into space occupied by a deleted clip when our test drive came online. The real removable-media test used a SanDisk Cruzer Switch formatted as exFAT on the AORUS Windows 11 x64 test machine. It simulated connection by taking the disk offline and online in software; it did not test physical unplugging and reconnecting.

Method and observations

TestBeforeAfter / result
Fixed virtual disk (VHDX)A deleted Tesla clip occupied the lowest free clusters on an exFAT volume.Across seven trials, Windows wrote System Volume Information within about 0.1–0.4 seconds of the volume coming online and overwrote the first two clusters of the deleted clip.
Real removable SanDisk driveA deleted clip occupied free clusters; the disk was brought online after being taken offline in software.The recorded test reported writes of System Volume Information, WPSettings.dat and IndexerVolumeGuid into the lowest free clusters, over the deleted clip, on every simulated connection. The correction does not give a trial count or timing for this device.

Protection experiments

mountvol /N prevented writes on the fixed virtual disk, but did not prevent writes on the removable SanDisk drive, including a volume new to Windows. That result supersedes the earlier proposed automount instructions.

Setting the disk read-only with diskpart before bringing it online prevented writes in the software simulation. This does not establish a practical step before physically plugging in a drive: a removable drive can come online immediately. No practical Windows USB mitigation is verified by these tests. The system-wide USB write-protect policy remains untested.

What the evidence supports

Deleted footage can remain in clusters marked free until new writes replace it. Our tests show that operating-system activity can be one such write source. ClipSalvage opening the source read-only does not stop writes made independently by Windows.

The results concern the tested environments and drive, not every Windows installation or USB device. We did not measure physical reconnect behavior, a universal loss rate, or the effect on all deleted clips. We did not establish that another operating system guarantees preservation.

Sources and limits

This is a sanitized transcription of the recorded September 25 test report and its September 26 removable-media correction, not a publication of private footage. The table separates the two test environments; it is not a raw sector dump or an independently repeated experiment.

The results above are transcribed from internal test reports. Raw sector logs are not published here and no independent replication is provided. No practical prevention instructions are published until a removable-media mitigation is tested.

If deleted footage matters

Stop further recording to the source and avoid copying new files onto it. Connecting it to a computer can introduce writes before recovery software opens it. If preservation is critical, seek help obtaining an image with a verified write-protection method; this article does not verify such a method.

Recovery guide · Support