کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456337 695696 2010 7 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Extracting Windows command line details from physical memory
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Extracting Windows command line details from physical memory
چکیده انگلیسی

Current memory forensic tools concentrate mainly on system-related information like processes and sockets. There is a need for more memory forensic techniques to extract user-entered data retained in various Microsoft Windows applications such as the Windows command prompt. The command history is a prime source of evidence in many intrusions and other computer crimes, revealing important details about an offender’s activities on the subject system. This paper dissects the data structures of the command prompt history and gives forensic practitioners a tool for reconstructing the Windows command history from a Windows XP memory capture. At the same time, this paper demonstrates a methodology that can be generalized to extract user-entered data on other versions of Windows.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 7, Supplement, August 2010, Pages S57–S63
نویسندگان
, ,