31.12.2014 Views

Slides (pdf) - Jesse Kornblum

Slides (pdf) - Jesse Kornblum

Slides (pdf) - Jesse Kornblum

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Computer Forensics Tool Marks<br />

• Anything detectable that software stores in RAM or on disk that<br />

identifies the tool in question<br />

– Most Recently Used lists<br />

– Header and footer carving<br />

– Registry keys left after program removed<br />

– Preferences files in user directories<br />

– Wiping programs leave traces behind

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!