Jump to content

Online Forensics of Win/32 System


Chris
 Share

Recommended Posts

You may need to check a live system to evaluate it for the initial response to a security incident.  This will be used to determine if a policy, law or other unacceptable use has occurred. The information found during this process could lead to human resource or legal actions. The following document will attempt to outline how to take volatile data from a live system before evidence is possibly lost. Many software programs are used in this evaluation these should not be installed  on the system under examination. They should be run from a "trusted file" source on the network, a CDROM or USB drive. All the files mentioned below can be downloaded from here win32forensic.zip.  It is important to limit the alteration of the system as much as possible.  If the evidence or case warrants further investigation, an in-depth forensic image may be taken for further evaluation.

More | Here

Anyone seen Quincy?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy