首页> 外文会议>IFIP WG 11.9 International Conference on Digital Forensics >A TOOL FOR EXTRACTING STATIC AND VOLATILE FORENSIC ARTIFACTS OF WINDOWS 8.x APPS
【24h】

A TOOL FOR EXTRACTING STATIC AND VOLATILE FORENSIC ARTIFACTS OF WINDOWS 8.x APPS

机译:用于提取Windows 8.x应用程序的静态和易失性法医伪影的工具

获取原文

摘要

Microsoft Windows 8 introduced lightweight sandboxed applications called "apps" that provide a full range of functionality on top of touch-enabled displays. Apps offer a wide range of functionality, including media editing, file sharing, Internet surfing, cloud service usage, online social media activities and audio/video streaming for the Windows 8 and 8.1 operating systems. The use of these apps produces much more forensically-relevant information compared with conventional application programs. This chapter describes MetroExtractor, a tool that gathers static and volatile forensic artifacts produced by Windows apps. The volatile artifacts are extracted from the hibernation and swap files available on storage media. MetroExtractor creates a timeline of user activities and the associated data based on the collected artifacts. The tool appears to be the first implementation for extracting forensically-sound static and volatile Windows 8 app artifacts from a system hard disk.
机译:Microsoft Windows 8引入了称为“Apps”的轻量级沙盒应用,该应用程序在启用触摸的显示屏上提供全方位的功能。应用程序提供广泛的功能,包括媒体编辑,文件共享,Internet冲浪,云服务使用,在线社交媒体活动和Windows 8和8.1操作系统的音频/视频流。与传统的应用程序相比,使用这些应用程序会产生更多的富集相关信息。本章介绍了MetroExtractor,该工具可以收集Windows应用程序产生的静态和易失性的法医伪影。从存储介质上可用的休眠和交换文件中提取挥发性伪像。 MetroExtractor基于所收集的工件创建用户活动的时间表和相关数据。该工具似乎是从系统硬盘中提取法对声音静态和易失性Windows 8应用程序伪影的第一个实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号