Chris Posted January 18, 2005 Report Share Posted January 18, 2005 You may need to check a live system to evaluate it for the initial response to a security incident. This will be used to determine if a policy, law or other unacceptable use has occurred. The information found during this process could lead to human resource or legal actions. The following document will attempt to outline how to take volatile data from a live system before evidence is possibly lost. Many software programs are used in this evaluation these should not be installed on the system under examination. They should be run from a "trusted file" source on the network, a CDROM or USB drive. All the files mentioned below can be downloaded from here win32forensic.zip. It is important to limit the alteration of the system as much as possible. If the evidence or case warrants further investigation, an in-depth forensic image may be taken for further evaluation.More | HereAnyone seen Quincy? Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.