首页> 美国政府科技报告 >Forensically Robust Memory Image Acquisition Protocol Based on Windows Memory Analysis.
【24h】

Forensically Robust Memory Image Acquisition Protocol Based on Windows Memory Analysis.

机译:基于Windows内存分析的法医鲁棒记忆图像采集协议。

获取原文

摘要

Collecting a forensically sound memory image from a 'live' system increases the effectiveness of the forensic investigation by providing analysts with enhanced data and context to extend the knowledge obtained from long term storage devices. * More, and better, data will most likely deliver better and more robust conclusions. * Enhanced understanding leads to better policy development and application. Why is it important. * Capability to inspect disks protected by whole disk encryption. * Recover passwords for files, folders, etc. without incurring in 'brute-force' methods. * Obtain 'up-to-date' data on actives processes. * Provide analysts with the capability to extract more information from the system by providing context to the 'swap' disk area. * Obtain active (and 'closing') network connections.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号