Quick pass vs sector search, when metadata is gone, and how NTFS/FAT differ in carved results. Includes verification checklists, RAM/pagefile cautions, and when hardware—not software—should come first.
Why TRIM changes the clock on SSDs, how external enclosures differ from internal NVMe, and when imaging beats guessing. BitLocker notes plus the questions teams ask in real incidents.
Stop-write discipline, readers vs laptop slots, adoptable storage pitfalls, and dual-slot camera workflows. Heat, counterfeits, and how to verify recovered video before you reformat the card.
What “excellent” really means, RAW bundles, VM disks, and how to explain risk to legal or finance. When to escalate hardware instead of re-scanning the same unstable cable.
Portable zips on locked PCs, antivirus and UAC, hash pinning, and air-gapped kits. Cleanup so cloud sync does not leak recovered data—and a handoff checklist for the next operator.
PST/OST realities, IMAP and eDiscovery first, Windows.old, and Mac migration leftovers. Verification in throwaway profiles plus when regulated data means “do not undelete locally.”
Ciphertext vs real recovery, containment before tools, immutable backups, and what not to do in a panic. Legal/insurance boundaries—Recuva is not a decryptor.
Storage Sense, OneDrive placeholders, WSL/Docker VHDX behavior, and triage order for temp-heavy apps. Long-term hygiene so the next “mystery delete” is rarer.
Letters vs mount points, WSL paths, USB enumeration after sleep, and Storage Spaces oddities. Screenshot habits so the next tech inherits facts—not folklore.
Shadow storage limits, File History vs cloud versions, apps that churn snapshots, and teaching users the two-click restore. When the list is empty, link forward to Deep Scan—not guilt.