Skip to content

Opening book details…

About this document

Understanding Volatile Data in Forensics by SADRONU is a document available to read on EtoBox.

This document discusses acquiring host-based evidence from computer systems for incident response investigations. It covers that modern operating systems like Windows leave traces of activity on systems that can provide evidence. It also notes that systems now have large storage capacities with potential evidence. The document recommends incident responders have the necessary tools to acquire evidence from systems locally, remotely, from live or offline systems. It provides guidelines for proper evidence co

Author
SADRONU
Language
EN