Windows Event Forensic Process.

ADVANCES IN DIGITAL FORENSICS X(2014)

引用 13|浏览13
暂无评分
摘要
Event logs provide an audit trail that records user events and activities on a computer and are a potential source of evidence in digital forensic investigations. This paper presents a Windows event forensic process (WinEFP) for analyzing Windows operating system event log files. The WinEFP covers a number of relevant events that are encountered in Windows forensics. As such, it provides practitioners with guidance on the use of Windows event logs in digital forensic investigations.
更多
查看译文
关键词
Windows event forensic process,Windows event logs
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要