Forensic Investigation.ppt

Forensic Investigation.ppt

Forensic Investigation Ben Hung Agenda Computer Evidence Collection using Forensic Tools People Evidence Collection through Forensic Interview Case Study Computer Evidence Collection 3 Phases Approach Phase 1: Preparation Phase 2: Data Collection Phase 3: Data Analysis Preparation Phase Data Collection Phase Tools Coroner’s Toolkit Grave robber Mactime Unrm Lazarus Mac robber (similar to grave-robber with –m option) Md5, lsof chkrootkit Data Collection Phase Run “grave-robber –v $mntpoint” on clone disk to collect initial data Will run set of tools under $TCT/lib. Run MacRobber or “grave-r

文档评论(0)

1亿VIP精品文档

相关文档