Forensic Artifacts of Microsoft Windows Vista System
2008; Springer Science+Business Media; Linguagem: Inglês
10.1007/978-3-540-69304-8_31
ISSN1611-3349
AutoresDaniel M. Purcell, Sheau-Dong Lang,
Tópico(s)Security and Verification in Computing
ResumoThis paper reviews changes made to Microsoft Windows Vista system from earlier Windows operating system (such as XP) and directs attention to system artifacts that are of evidentiary values in typical computer forensics work. The issues addressed include: NTFS on-disk structure, file system's directory structures, symbolic links, and recycle bin; we also briefly mention artifacts related to Windows mail, paging file, thumbnail caching, and print spooling.
Referência(s)