July 2004
Intermediate to advanced
480 pages
11h 40m
English
Non-volatile information does not necessarily need to be collected from a system at the same time as the volatile information. Because of the nature of non-volatile information, it should generally remain unchanged if the system is rebooted. However, this information can be collected at the same time as the volatile information, depending upon the needs of the investigator. Methodologies for collecting both types of information will be addressed in greater detail in Chapter 6, Developing a Methodology, and Chapter 7, Knowing What To Look For.
Many times, the contents of files provide valuable information regarding the nature of an incident. If an attack occurs against an IIS web server, ...
Read now
Unlock full access