官术网_书友最值得收藏!

Examination

The examination phase details the specific tools and forensic techniques that are utilized to discover and extract data from the evidence that is seized as part of the incident. For example, in a case where malware is suspected of infecting a desktop system as part of a larger attack, the extraction of specific information from an acquired memory image would take part in this stage. In other cases, digital forensic examiners may need to extract Secure Shell (SSH) traffic from a network capture. The examination of digital evidence also continues the process of proper preservation in that examiners maintain the utmost care with the evidence during the examination. If the digital forensic examiner does not take care in the preservation of the evidence in this stage, there is the possibility of contamination that would result in the evidence being unreliable or unusable.

主站蜘蛛池模板: 东台市| 涡阳县| 大荔县| 沙坪坝区| 苍山县| 垣曲县| 丽水市| 延川县| 疏附县| 锦州市| 宝清县| 弋阳县| 巴彦淖尔市| 竹山县| 永清县| 咸丰县| 莱西市| 即墨市| 普洱| 黄石市| 烟台市| 西乌| 屏山县| 湖南省| 观塘区| 定结县| 阜平县| 东乡县| 延川县| 定南县| 汶上县| 江华| 子长县| 招远市| 佳木斯市| 淮阳县| 九江市| 河南省| 德兴市| 华坪县| 甘孜县|