Добавил:
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
4-1 Основи цифрової криміналістики / лк / lecture 7. Аналіз артефактів Windows.pptx
Скачиваний:
119
Добавлен:
02.02.2021
Размер:
6.15 Mб
Скачать

RESTORE POINTS vs. VOLUME SHADOW COPY

• History of Restore Points & Volume Shadow Copy

RESTORE POINTS vs. VOLUME SHADOW COPY

History of Restore Points & Volume Shadow Copy

Benefits for Windows operating system

Client vs. Server side of Windows operating systems

Location of Restore Points & Volume Shadow Copy

RESTORE POINTS (Windows XP)

RESTORE POINTS (Windows 7)

RESTORE POINTS vs. VOLUME SHADOW COPY

History of Restore Points & Volume Shadow Copy

Benefits for Windows operating system

Client vs. Server side of Windows operating systems

Location of Restore Points & Volume Shadow Copy

Restore Point & Volume Shadow Copy Settings

RESTORE POINTS (Windows XP)

HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SystemRestore

RESTORE POINTS vs. VOLUME SHADOW COPY

History of Restore Points & Volume Shadow Copy

Benefits for Windows operating system

Client vs. Server side of Windows operating systems

Location of Restore Points & Volume Shadow Copy

Restore Point & Volume Shadow Copy Settings

Evidentiary value of being able to examine Restore Points &Volume Shadow Copy

VOLUME SHADOW COPY

Shadow Explorer ver.0.9

vssadmin

vssadmin list shadows /for=C:

mklink /d c:\sc1 \\?\GLOBALROOT\Device\ HarddiskVolumeShadowCopy7\

PDE – Physical Disk Emulator in EnCase v.7