首页> 外文会议>International Conference on Future Generation Communication and Networking >Windows Pagefile Collection and Analysis for a Live Forensics Context
【24h】

Windows Pagefile Collection and Analysis for a Live Forensics Context

机译:Windows PageFile收集和实时取证上下文的分析

获取原文

摘要

The aim of this paper is to present a new tool, the Page- file Collection Tool (PCT), which can be used to obtain a pagefile on a live Windows based system. It is a known fact that a pagefile on a live system is protected by the operat- ing system, which uses it in the virtual memory context. By using the NTFS filesystem specifications we were able to re- construct the full pagefile, which can be used by a forensics expert to carve out further and precious information in the memory analysis field.
机译:本文的目的是呈现一个新工具,页面文件收集工具(PCT),可用于在基于Windows的系统上获取页面文件。这是一个已知的事实,即现场系统上的页面文件由操作系统保护,该系统在虚拟内存上下文中使用它。通过使用NTFS文件系统规范,我们能够重新构建完整页面文件,该文件可以由取证专家使用,以便在内存分析字段中探讨进一步和珍贵的信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号