Tool review – remote forensic preservation and examination tools

Détails

Ressource 1Télécharger: 1-s2.0-S1742287604000866-main.pdf (1190.12 [Ko])
Etat: Public
Version: Final published version
ID Serval
serval:BIB_220777E3BDF1
Type
Article: article d'un périodique ou d'un magazine.
Collection
Publications
Titre
Tool review – remote forensic preservation and examination tools
Périodique
Digital Investigation
Auteur(s)
Casey Eoghan, Stanley Aaron
ISSN
1742-2876
Statut éditorial
Publié
Date de publication
2004
Volume
1
Numéro
4
Pages
284-297
Langue
anglais
Résumé
Forensic tools are emerging to help digital investigators preserve evidence on live, remote systems. These tools are applying the precepts of digital forensics to incident response, enterprise policy enforcement, and electronic data discovery. This paper discusses the strengths and shortcomings of ProDiscover IR and EnCase Enterprise Edition in the context of the overall digital investigation process. In addition, a test scenario of a security breach involving a Windows rootkit is used to evaluate the capabilities of these tools. Based on this review, a comparison table is provided and several enhancements are proposed for tools used to process digital evidence on remote, live systems.
Mots-clé
Remote digital forensics, Live digital forensics, Incident response, Electronic data discovery, Computer forensics
Création de la notice
16/01/2019 22:48
Dernière modification de la notice
20/08/2019 13:58
Données d'usage