官术网_书友最值得收藏!

Examination

The examination phase details the specific tools and forensic techniques that are utilized to discover and extract data from the evidence that is seized as part of the incident. For example, in a case where malware is suspected of infecting a desktop system as part of a larger attack, the extraction of specific information from an acquired memory image would take part in this stage. In other cases, digital forensic examiners may need to extract Secure Shell (SSH) traffic from a network capture. The examination of digital evidence also continues the process of proper preservation in that examiners maintain the utmost care with the evidence during the examination. If the digital forensic examiner does not take care in the preservation of the evidence in this stage, there is the possibility of contamination that would result in the evidence being unreliable or unusable.

主站蜘蛛池模板: 彭山县| 卢龙县| 加查县| 鄂托克前旗| 得荣县| 两当县| 南澳县| 安乡县| 商水县| 青浦区| 武清区| 巧家县| 宜都市| 建阳市| 历史| 镇安县| 崇左市| 建昌县| 临高县| 勐海县| 天气| 合川市| 璧山县| 临夏市| 青浦区| 济宁市| 彭阳县| 朝阳县| 巴林右旗| 神农架林区| 鲜城| 吉木萨尔县| 芜湖市| 旺苍县| 美姑县| 兰考县| 册亨县| 南江县| 汝南县| 响水县| 江山市|