O'Reilly logo

Windows Forensics Cookbook by Scar de Courcier, Oleg Skulkin

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

How to do it...

The following steps need to be followed to perform forensics on OneDrive:

  1. Open your forensic software of choice and navigate to the relevant folder, depending on whether you are using a smartphone or a computer for forensic analysis (see the previous paragraphs for details).
  2. The backend of the OneDrive folder is actually not of particular forensic interest. In the logs folder listed above you will find two subfolders: Common and Personal. The Common folder lists all elements the operating system automatically runs, namely StandaloneUpdater and telemetryCache files. These refer to automated updates to OneDrive.
Fig 10.5 StandaloneUpdater ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required