官术网_书友最值得收藏!

Examination

The examination phase details the specific tools and forensic techniques that are utilized to discover and extract data from the evidence that is seized as part of the incident. For example, in a case where malware is suspected of infecting a desktop system as part of a larger attack, the extraction of specific information from an acquired memory image would take part in this stage. In other cases, digital forensic examiners may need to extract Secure Shell (SSH) traffic from a network capture. The examination of digital evidence also continues the process of proper preservation in that examiners maintain the utmost care with the evidence during the examination. If the digital forensic examiner does not take care in the preservation of the evidence in this stage, there is the possibility of contamination that would result in the evidence being unreliable or unusable.

主站蜘蛛池模板: 汾阳市| 乐陵市| 靖州| 宁河县| 冕宁县| 南丹县| 长海县| 平顺县| 临桂县| 吉水县| 天台县| 铁岭县| 张家口市| 东山县| 兰考县| 桐乡市| 上饶县| 澄迈县| 张家港市| 马关县| 涪陵区| 乳山市| 青铜峡市| 荥阳市| 彝良县| 遵义市| 鸡东县| 陇川县| 拉萨市| 英超| 连江县| 庄浪县| 金平| 盱眙县| 张掖市| 米林县| 清丰县| 中西区| 岳普湖县| 双江| 花垣县|