This study aims to compare the effectiveness and efficiency of the disk overwrite method and the default factory reset feature as an anti-forensic technique on Android devices. The data collection process in this study was carried out by an experimental process on Android 10 devices, which had gone through each anti-forensic technique process in turn before attempting to recover deleted data using the Photorec software. From the experimental results, it was found that the recovery process yielded nearly identical results between the use of the disk overwrite method, be it 1-pass, 3-pass, 7-pass, or 35-pass, and the default factory reset method, although in terms of operating times there was a stark difference between the five. In other words, the use of the disk overwrite method as an anti-forensic technique in normal cases does not provide any added value compared to the default Android factory reset feature. The results of this study can be used as a guide and reference by new digital forensics practitioners before processing electronic evidence in the form of Android devices. In addition, the results of this study can serve as empirical evidence of the effectiveness and efficiency of the default factory reset feature on Android devices in maintaining user privacy when the device changes ownership.
                        
                        
                        
                        
                            
                                Copyrights © 2022