July 2004
Intermediate to advanced
480 pages
11h 40m
English
There is a good deal of volatile information on a live system that an administrator or investigator can use to determine what may have occurred during the incident. This information can be used for general troubleshooting purposes or as part of an investigation. This information is usually retained in memory while the system is operating and tends to disappear when the system is shut down. Volatile information generally consists of:
System time
Logged on user(s)
Process information
Network connections
Network status
Clipboard contents
Command history
Service/driver information
All of this information in its various forms can be retrieved using freeware utilities, tools native to the systems, and Perl scripts. ...
Read now
Unlock full access