The Experts below are selected from a list of 228 Experts worldwide ranked by ideXlab platform
Leventhal Paul - One of the best experts on this subject based on the ideXlab platform.
-
\NCI addresses\
2003Co-Authors: Leventhal PaulAbstract:Image of the following Directory: Partition 1\NONAME [FAT32]\[root]\NCI addresses\Dolph Briscoe Center for American Histor
-
\Aftergood Secrecy News\
2003Co-Authors: Leventhal PaulAbstract:Image of the following Directory: Partition 1\NONAME [FAT32]\[root]\Aftergood Secrecy News\Dolph Briscoe Center for American Histor
-
\CARNEGIE PROLIF NEWS\
2003Co-Authors: Leventhal PaulAbstract:Image of the following Directory: Partition 1\NONAME [FAT32]\[root]\CARNEGIE PROLIF NEWS\Dolph Briscoe Center for American Histor
-
\MISC NEWS\
2003Co-Authors: Leventhal PaulAbstract:Image of the following Directory: Partition 1\NONAME [FAT32]\[root]\MISC NEWS\Dolph Briscoe Center for American Histor
-
\Greenpeace PU News\
2003Co-Authors: Leventhal PaulAbstract:Image of the following Directory: Partition 1\NONAME [FAT32]\[root]\Greenpeace PU News\Dolph Briscoe Center for American Histor
Paul Leventhal - One of the best experts on this subject based on the ideXlab platform.
-
Aftergood Secrecy News
2003Co-Authors: Paul LeventhalAbstract:Image of the following Directory: Partition 1\NONAME [FAT32]\[root]\Aftergood Secrecy News\
K. L. Thomas - One of the best experts on this subject based on the ideXlab platform.
-
SNDS - Towards Retrieving Live Forensic Artifacts in Offline Forensics
Communications in Computer and Information Science, 2012Co-Authors: S Dija, T. R. Deepthi, C. Balan, K. L. ThomasAbstract:Live Forensics is the process of collecting forensically sound evidence from the suspect’s computer system when it is in running state. But, this process is not widely accepted as a cyber forensic procedure in most of the countries. Instead of starting with a live forensic procedure, usually a traditional offline forensics is adopted according to the accepted cyber forensic procedure. This involves pulling the power plug of the suspect’s system and imaging the storage media. The crucial evidence available in the running system is lost forever when turning off the system. The most important information that can be collected in live forensics is the evidence available in the Random Access Memory of a system. Since a Windows operating system adds footprints of each of its current activity in RAM, analyzing its content is indispensable in a cyber forensic analysis. And, this may provide information that can be crucial in carrying out further investigation. Since RAM content is highly volatile, its complete content is lost when turning off the system. In this paper a methodology to retrieve memory forensic artifacts while adopting a traditional offline forensics is explained. This is done by analyzing the hibernation file available in windows Directory Partition inside the hard disk of the suspect’s system.
S Dija - One of the best experts on this subject based on the ideXlab platform.
-
SNDS - Towards Retrieving Live Forensic Artifacts in Offline Forensics
Communications in Computer and Information Science, 2012Co-Authors: S Dija, T. R. Deepthi, C. Balan, K. L. ThomasAbstract:Live Forensics is the process of collecting forensically sound evidence from the suspect’s computer system when it is in running state. But, this process is not widely accepted as a cyber forensic procedure in most of the countries. Instead of starting with a live forensic procedure, usually a traditional offline forensics is adopted according to the accepted cyber forensic procedure. This involves pulling the power plug of the suspect’s system and imaging the storage media. The crucial evidence available in the running system is lost forever when turning off the system. The most important information that can be collected in live forensics is the evidence available in the Random Access Memory of a system. Since a Windows operating system adds footprints of each of its current activity in RAM, analyzing its content is indispensable in a cyber forensic analysis. And, this may provide information that can be crucial in carrying out further investigation. Since RAM content is highly volatile, its complete content is lost when turning off the system. In this paper a methodology to retrieve memory forensic artifacts while adopting a traditional offline forensics is explained. This is done by analyzing the hibernation file available in windows Directory Partition inside the hard disk of the suspect’s system.
T. R. Deepthi - One of the best experts on this subject based on the ideXlab platform.
-
SNDS - Towards Retrieving Live Forensic Artifacts in Offline Forensics
Communications in Computer and Information Science, 2012Co-Authors: S Dija, T. R. Deepthi, C. Balan, K. L. ThomasAbstract:Live Forensics is the process of collecting forensically sound evidence from the suspect’s computer system when it is in running state. But, this process is not widely accepted as a cyber forensic procedure in most of the countries. Instead of starting with a live forensic procedure, usually a traditional offline forensics is adopted according to the accepted cyber forensic procedure. This involves pulling the power plug of the suspect’s system and imaging the storage media. The crucial evidence available in the running system is lost forever when turning off the system. The most important information that can be collected in live forensics is the evidence available in the Random Access Memory of a system. Since a Windows operating system adds footprints of each of its current activity in RAM, analyzing its content is indispensable in a cyber forensic analysis. And, this may provide information that can be crucial in carrying out further investigation. Since RAM content is highly volatile, its complete content is lost when turning off the system. In this paper a methodology to retrieve memory forensic artifacts while adopting a traditional offline forensics is explained. This is done by analyzing the hibernation file available in windows Directory Partition inside the hard disk of the suspect’s system.