OSForensics™ includes built-in support for accessing Volume Shadow Copies. Shadow copies provide a glimpse of the volume at a point in time in the past. This will allow for discovery of changes to files and even view possible deleted files.
Shadow Copies within OSForensics' built in File System Browser
The File System Browser provides an explorer-like view of all devices that have been added to the case. Unlike Windows Explorer, additional forensic-specific information is provided along with the integration with OSForensics' functionality.
Normal File System Browser Behavior.
File System Browser with Shadow copies enabled. Previous copies are shown in Grey.