Загрузка страницы

The Volume Shadow Knows

As a continuation of the "Introduction to Windows Forensics" series, this episode covers Volume Shadows and how they can be a forensic goldmine for the investigator. We'll first look at the basics of the technology, and then we'll revisit a concept from an earlier 13Cubed episode and look at two different ways to mount Volume Shadow Copies on a live Windows system. Then, we'll look at how we can mount and interact with these artifacts from a disk image via the "libvshadow" library and its associated utilities.

*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***

VSCMount:
https://ericzimmerman.github.io/

SANS SIFT Workstation:
https://github.com/sans-dfir/sift-cli

Background Music Courtesy of Anders Enger Jensen:
https://www.youtube.com/user/HariboOSX

#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics

Видео The Volume Shadow Knows канала 13Cubed
Показать
Комментарии отсутствуют
Введите заголовок:

Введите адрес ссылки:

Введите адрес видео с YouTube:

Зарегистрируйтесь или войдите с
Информация о видео
6 мая 2019 г. 15:59:40
00:14:48
Яндекс.Метрика