SANS Poster Artifact Analysis, Windows XP/7

by butsch 25. October 2012 17:35

SANS has released a genius post with a lot of Windows XP/Win7 reference and paths. For everyone who has to do with Antivirus this may be a good help.

It gives you also a good overview of Windows 7 paths and locations.

  • Index.dat
  • Sykpe History
  • Prefetch Apps
  • NLA Network Cache (See to which network the laptop had connection the last few days)
  • Flash Player Paths and Cache

https://blogs.sans.org/computer-forensics/files/2012/06/SANS-Digital-Forensics-and-Incident-Response-Poster-2012.pdf

Tags:

Comments are closed

Werbung von Drittfirmen (Nicht Butsch Informatik):

Werbung von Drittfirmen via Google Adsense: