The Experts below are selected from a list of 12 Experts worldwide ranked by ideXlab platform
Kimkwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.
-
ATCS/SePrIoT@SecureComm - Identification of Forensic Artifacts in VMWare Virtualized Computing
Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2018Co-Authors: Cory Smith, Glenn B. Dietrich, Kimkwang Raymond ChooAbstract:With popularity of virtualized computing continuing to grow, it is crucial that digital forensic knowledge keeps pace. This research sought out to identify the forensic artifacts and their locations that may be recovered from a VMware Workstation virtual machine running Windows 7 x64. Several common forensic tools were used to conduct this research, namely AccessData’s Forensic Toolkit (FTK), FTK Imager, and FTK Registry Viewer. This research verified the processes required to gather digital evidence from a virtual machine disk (VMDK) file, creation of a forensic image, and mounting of evidence into these forensic tools. This research then proceeded to document recovered artifacts and their locations related to system configuration, internet usage, file creation and deletion, user administration, and more.
-
identification of forensic artifacts in vmware virtualized computing
International Conference on Security and Privacy in Communication Systems, 2017Co-Authors: Cory Smith, Glenn Dietrich, Kimkwang Raymond ChooAbstract:With popularity of virtualized computing continuing to grow, it is crucial that digital forensic knowledge keeps pace. This research sought out to identify the forensic artifacts and their locations that may be recovered from a VMware Workstation virtual machine running Windows 7 x64. Several common forensic tools were used to conduct this research, namely AccessData’s Forensic Toolkit (FTK), FTK Imager, and FTK Registry Viewer. This research verified the processes required to gather digital evidence from a virtual machine disk (VMDK) file, creation of a forensic image, and mounting of evidence into these forensic tools. This research then proceeded to document recovered artifacts and their locations related to system configuration, internet usage, file creation and deletion, user administration, and more.
Cory Smith - One of the best experts on this subject based on the ideXlab platform.
-
ATCS/SePrIoT@SecureComm - Identification of Forensic Artifacts in VMWare Virtualized Computing
Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2018Co-Authors: Cory Smith, Glenn B. Dietrich, Kimkwang Raymond ChooAbstract:With popularity of virtualized computing continuing to grow, it is crucial that digital forensic knowledge keeps pace. This research sought out to identify the forensic artifacts and their locations that may be recovered from a VMware Workstation virtual machine running Windows 7 x64. Several common forensic tools were used to conduct this research, namely AccessData’s Forensic Toolkit (FTK), FTK Imager, and FTK Registry Viewer. This research verified the processes required to gather digital evidence from a virtual machine disk (VMDK) file, creation of a forensic image, and mounting of evidence into these forensic tools. This research then proceeded to document recovered artifacts and their locations related to system configuration, internet usage, file creation and deletion, user administration, and more.
-
identification of forensic artifacts in vmware virtualized computing
International Conference on Security and Privacy in Communication Systems, 2017Co-Authors: Cory Smith, Glenn Dietrich, Kimkwang Raymond ChooAbstract:With popularity of virtualized computing continuing to grow, it is crucial that digital forensic knowledge keeps pace. This research sought out to identify the forensic artifacts and their locations that may be recovered from a VMware Workstation virtual machine running Windows 7 x64. Several common forensic tools were used to conduct this research, namely AccessData’s Forensic Toolkit (FTK), FTK Imager, and FTK Registry Viewer. This research verified the processes required to gather digital evidence from a virtual machine disk (VMDK) file, creation of a forensic image, and mounting of evidence into these forensic tools. This research then proceeded to document recovered artifacts and their locations related to system configuration, internet usage, file creation and deletion, user administration, and more.
Glenn Dietrich - One of the best experts on this subject based on the ideXlab platform.
-
identification of forensic artifacts in vmware virtualized computing
International Conference on Security and Privacy in Communication Systems, 2017Co-Authors: Cory Smith, Glenn Dietrich, Kimkwang Raymond ChooAbstract:With popularity of virtualized computing continuing to grow, it is crucial that digital forensic knowledge keeps pace. This research sought out to identify the forensic artifacts and their locations that may be recovered from a VMware Workstation virtual machine running Windows 7 x64. Several common forensic tools were used to conduct this research, namely AccessData’s Forensic Toolkit (FTK), FTK Imager, and FTK Registry Viewer. This research verified the processes required to gather digital evidence from a virtual machine disk (VMDK) file, creation of a forensic image, and mounting of evidence into these forensic tools. This research then proceeded to document recovered artifacts and their locations related to system configuration, internet usage, file creation and deletion, user administration, and more.
Eric Zimmerman - One of the best experts on this subject based on the ideXlab platform.
-
the xwf internal hash database and the Registry Viewer
X-Ways Forensics Practitioner’s Guide, 2014Co-Authors: Brett Shavers, Eric ZimmermanAbstract:This chapter details using hash sets to identify, compare, and optionally hide files based on known hash values. You can save a considerable amount of time when thorough hash sets are available for certain types of investigations. X-Ways Forensics (XWF) contains robust hashing capabilities that allow for quickly finding items of interest or eliminating nonpertinent files in a case. There is virtually no limit to the number of individual hash sets that you can create in XWF.
Brett Shavers - One of the best experts on this subject based on the ideXlab platform.
-
the xwf internal hash database and the Registry Viewer
X-Ways Forensics Practitioner’s Guide, 2014Co-Authors: Brett Shavers, Eric ZimmermanAbstract:This chapter details using hash sets to identify, compare, and optionally hide files based on known hash values. You can save a considerable amount of time when thorough hash sets are available for certain types of investigations. X-Ways Forensics (XWF) contains robust hashing capabilities that allow for quickly finding items of interest or eliminating nonpertinent files in a case. There is virtually no limit to the number of individual hash sets that you can create in XWF.