Tool review – remote forensic preservation and examination tools

Details

Ressource 1Download: 1-s2.0-S1742287604000866-main.pdf (1190.12 [Ko])
State: Public
Version: Final published version
Serval ID
serval:BIB_220777E3BDF1
Type
Article: article from journal or magazin.
Collection
Publications
Title
Tool review – remote forensic preservation and examination tools
Journal
Digital Investigation
Author(s)
Casey Eoghan, Stanley Aaron
ISSN
1742-2876
Publication state
Published
Issued date
2004
Volume
1
Number
4
Pages
284-297
Language
english
Abstract
Forensic tools are emerging to help digital investigators preserve evidence on live, remote systems. These tools are applying the precepts of digital forensics to incident response, enterprise policy enforcement, and electronic data discovery. This paper discusses the strengths and shortcomings of ProDiscover IR and EnCase Enterprise Edition in the context of the overall digital investigation process. In addition, a test scenario of a security breach involving a Windows rootkit is used to evaluate the capabilities of these tools. Based on this review, a comparison table is provided and several enhancements are proposed for tools used to process digital evidence on remote, live systems.
Keywords
Remote digital forensics, Live digital forensics, Incident response, Electronic data discovery, Computer forensics
Create date
16/01/2019 22:48
Last modification date
20/08/2019 13:58
Usage data