Bruce Nikkel App_forensic_artifacts.pdf
Wähle die Ordner aus, zu welchen Du "Bruce Nikkel App_forensic_artifacts.pdf" hinzufügen oder entfernen möchtest
Name some common user applications.
name some examples of professional applications that leave artifacts
what are some special intrest apps that leave traces?
application forensic analysis involves the examination of what?
Application forensic analysis involves examination of:
What are some charecteristics of application data files?
what does the linux file command do?
The linux file command is used to identify file formats
What should you always do when viewing typical files (office documents, pictures, music, etc...) with a standard viewers?
Always use a write-blocker or read only image to prevent data being writen do the image by viewers.
What are the problems when dealing with proprietary formats?
What meta data can be found in files? (not from filesystem)
What is EXIF data?
EXIF - EXchangeable Imagefile Format
What is the goal of deeper analysis of executable files?
The goal is to understand exactly what th program is doing (without having the original source code)
What could be gained from a deep analysis of an executable and what could be a problem in doing so?
What could be gained:
What is static analysis?
Static analysis is when you:
What is dynamic analysis?
Dynamic analysis is when you:
Why is malware analysis not always done?
Malware analysis is a time consuming task requiring good knowledge of operating systems and how programs are compiled into assembly language.
Paul Baumgartner - Lehrmittel für Elektroberufe
Lernen bei den Erfolgreichsten
Anatomie lernen - einfach, schnell und online
Berufs- und Weiterbildungszentrum