LayerOne 2008 – Diane Barrett – Virtual Traces



This presentation will explore all the newest methods for virtualized environments and the implications they have on the world of forensics. It will begin by describing and differentiating between software and hardware virtualization. It will then move on to explain the various methods used for server and desktop virtualization. Next, it will describe the fundamentals of a traditional forensic investigation and explain why artifacts are difficult to find using traditional processes. Finally, it will describe some common methods to find virtualization artifacts and identify virtual activities.


- Post Time: 11-09-16 - By: http://www.rfidang.com