错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Finding Artifacts

  • Joakim Kävrestad,
  • Marcus Birath,
  • Nathan Clarke

摘要

The essence of any forensic examinationExamination is to look for data, artifactsArtifact. While it is impossible to describe all possible artifactsArtifact that may be of interest in any given investigation, this chapter aims to describe how to find some artifactsArtifact that are very common to look for. The chapter first describes how to find information such as install dateInstall date and time zoneTime zone settings from the Windows registryWindows Registry. Next, the chapter provides a rather detailed description of how to analyze a partitionPartition table in order to ensure that all drive space is allocated to a partitionPartition. An overview of how to search for deleted filesDeleted files is also included. A lot of good information can be found in file metadataMetadata, which includes information such as when a file was created and by whom. AnalyzingAnalyzing different kinds of metadataMetadata is described before the chapter presents an approach on how to analyze logLog files. At the end by presenting ways to analyze other useful types of information such as link files and thumbcachesThumbcache.