Developing a Fundamental Computer Investigation Process for Windows

Added by the EDUCAUSE Librarian
Title:Developing a Fundamental Computer Investigation Process for Windows (ID: SEC07004)
Author(s):Barbara Chung (Microsoft Corporation)
Topics:Computer Forensics, Operating Systems, Security Management
Origin:Presented at Security Professionals Conference (04/12/2007)
Type:Presentations/Speeches
Abstract:This session will introduce a multiphase model based on well-accepted procedures in the computer investigation community. We will also discuss the use of Windows Sysinternals tools (advanced utilities that can be used to examine Windows•based computers) as well commonly available Windows commands and tools to assist in the investigation process.
View this resource: