EVALUATION OF REGISTRY DATA REMOVAL BY SHREDDER PROGRAMS
|
|
|
- Adam Knight
- 10 years ago
- Views:
Transcription
1 Chapter 5 EVALUATION OF REGISTRY DATA REMOVAL BY SHREDDER PROGRAMS Harry Velupillai and Pontjho Mokhonoana Abstract Shredder programs attempt to overcome Window s inherent inability to erase data completely. A shredder is useful when one needs to transfer ownership or dispose of a computer, but it can be exploited bya suspect for the purpose of wiping incriminating evidence. Most shredder programs claim to remove all traces of data. This paper examines these claims by conducting forensic examinations of computers on which shredder programs were used. Keywords: Shredder tools, Windows Registry, data removal 1. Introduction It is difficult to completely remove all traces of data from a computer system [9]. In the case of Microsoft Windows, for example, much of the erased data is recoverable, even when it is not visible from the Windows Explorer interface. For example, traces of a program remain after deleting it using Window s Add/Remove Programs function. Generally, the residual data takes little space and users are not concerned about this data unless it affects system performance. The situation has changed with the release of digital forensic tools [10], which enable users to locate, recover and interpret deleted data. Initially, forensic tools were only available to law enforcement personnel; now, high performance tools are available to all at relatively low cost. The implications are obvious data must not simply be removed, it must be removed securely. Also, data should be removed from locations that may not be quite so obvious. Shredder programs were developed to address Window s inherent inability to erase data completely. These programs claim to wipe all traces of sensitive data, including data residing in locations that normal users
2 52 ADVANCES IN DIGITAL FORENSICS IV would not access (e.g., the Windows Registry). This paper examines the effectiveness of shredder programs available on the market. In particular, it evaluates their ability to completely remove Windows Registry entries. Several digital forensic tools, including a hex editor, are used to determine if deleted entries are still visible after shredder programs are executed. 2. Windows Registry The Windows Registry is a directory that stores settings and options for all the hardware, software and users of a Windows system. Changes to control panel settings, file associations and installed software and applications are maintained in the registry. The registry files are in continuous use when the machine is running; changes to the registry are made in real time and timestamps are changed only at shutdown. Registry data is stored in multiple files whose names and locations differ according to the specific Windows edition [2, 6]. Windows 3.11: The registry is stored in only one file Reg.dat, which is located in the directory C:\Windows. Windows 95/98: The registry consists of two files, User.dat and System.dat, whicharestoredinthedirectoryc:\windows. Windows ME: The registry consists of three files, User.dat, System.dat and Classes.dat, whicharestoredinthedirectory C:\Windows. Other Windows Versions: The registry of Windows versions released after Windows ME (excluding Vista) have six files, Default, Sam, Security, Software, System and Userdiff, whicharestored in the directory %SystemRoot%\System32\Config. Note that these files do not have extensions. In addition, each user has two files, Ntuser.dat and Usrclass.dat, storedinthecorrespondinguser profile directory. The problem with registry data is that the user knows where the files are located, but he cannot wipe them because they are vital to Windows hemightaswellre-installtheoperatingsystem.thisiswhyshredder programs are required. 3. Shredder Programs and Forensic Tools This section describes the shredder programs and digital forensic tools used in our experiments.
3 Velupillai & Mokhonoana Shredder Programs Numerous shredder programs are available from commercial sources or are downloadable from the Internet. We selected two representative programs, CCleaner [13], which is available as freeware; and Registry Washer [14], a commercial product. 3.2 Forensic Analysis Tools Several digital forensic tools [8] were used to evaluate the ability of the shredder programs to delete registry data. Ultimate Toolkit: This popular toolkit from Accessdata [4] consists of the FTK Imager, Registry Viewer, Password Recovery Toolkit (PRTK), Distributed Network Attack (DNA) and Forensic Toolkit (FTK). Only the FTK Imager and Registry Viewer were used in our tests. FTK Imager: FTK Imager is a forensic tool for recovering evidence from a target machine [1]. The tool can create physical and logical images of drives in a number of formats. In addition, it can extract registry files from a running machine. Because FTK Imager accesses the drive directly instead of via the operating system interface, it is able to acquire the locked system files used by the registry. Registry Viewer: The Registry Viewer is a forensic tool for viewing all Windows Registry files [3]. It provides access to user data, hardware and software information, URL/MRU lists and the Protected System Storage Provider. Regedit: This Windows Registry editor is a built-in utility for viewing and editing registry entries [12]. Regedit permits the addition, modification and deletion of registry entries. 4. Experimental Setup and Results The experiments involved installing and then uninstalling emule [7], a popular peer-to-peer program. While peer-to-peer programs canbeused for illegal activities, our focus was on determining whether ornotthe shredder programs could remove all traces of emule from the Windows Registry.
4 54 ADVANCES IN DIGITAL FORENSICS IV Figure 1. emule key in the registry. 4.1 Installation When installed, emule creates eight entries in file Ntuser.dat in the Windows Registry. Note that Windows Registry folders are called keys. Entry 1 (Key): The emule key is located at Software\Emule (Figure 1). Entries 2, 3 and 4 are located inside this key.
5 Velupillai & Mokhonoana 55 Figure 2. Entries 2, 3 and 4 in the Registry Entry 2 (String Value): This entry is found in Software\Emule \Install Path (Figure 2). The first entry Default is ignored because it is created by the Windows Registry, not by emule; also, it does not contain any data. Of the three entries created under the emule key, only Entry 2 holds sensitive data. Entry 3 (StringValue): This entry is found in Software\Emule \Installer Language. Entry 4 (Dword Value): This entry is found in Software\Emule \UsePublicUserDirectories. Entry 5 (Key): This entry is at Software\Microsoft\Windows \CurrentVersion\Explorer\MenuOrder\StartMenu\Programs\E mule. Figure 3. Entry 6 in the registry. Entry 6 (Binary Value) This entry, created under Entry 5, is at Software\Microsoft\Windows\CurrentVersion\Explorer \MenuOrder\StartMenu\Programs\Emule\Order. Figure3shows the entry; note that the default entry is ignored. Entry 7 (String Value): This entry is at Software\Microsoft\ Windows\ShellNoRoam\MuiCache\C:\Program Files\eMule\emu le.exe. ThisentrypointstothelocationoftheeMuleexecutable and it is added only if emule is executed. Entry 8 (String Value): This entry is at Software\Microsoft\ Windows\ShellNoRoam\MuiCache\O:\LocalDriveC\downloads\e Mule0.48a-Installer.exe. ItpointstothelocationoftheeMule installation file.
6 56 ADVANCES IN DIGITAL FORENSICS IV Table 1. Comparison of shredder programs. Entry Windows CCleaner Registry Washer 1 Removed 2 Removed 3 Removed 4 Removed 5 Not Removed Not Removed 6 Not Removed Not Removed 7 Removed Removed 8 Conditional Removal Conditional Removal 4.2 Uninstallation Several entries are removed after Windows is used to uninstall emule. However, Entries 5,6,7 and 8 remain. 4.3 Evaluation of Shredder Programs Both the shredder programs removed Entry 7. Entry 8 was removed only when the emule installer had been deleted or moved to a different directory. However, both programs did not remove Entries 5 and 6. The results are summarized in Table 1. Analysis of the results sheds light on how shredder programs work and why they fail to remove all traces of a program. Shredders attempt to find data that should be removed mainly by searching for broken links. This is why Entry 8 was removed only when the installation file had been deleted or moved. Entries 5 and 6 were not removed because they did not contain links to programs, just data used by programs. 4.4 Forensic Acquisition The final step in the experiments was to use forensic tools to see if the deleted portions of the registry could be reconstructed. Ourtests showed that it was not possible to recover any data deleted by the two shredders or manually using Regedit. The fact that the data deleted using Regedit was also not recoverable indicates some other mechanism is at work perhaps the way Windows stores and changes registry files. We intend to investigate this issue in future work. 5. Advantages and Limitations Using shredder programs has several advantages. CCleaner was very effective at wiping the detailed history maintained by Windows. Also,
7 Velupillai & Mokhonoana 57 CCleaner s secure deletion facility enables users to delete dataaswellas to overwrite the sectors that held the data to prevent any recovery [5, 9]. Moreover, it allows users to choose the number of overwrites based on the sensitivity of the data being erased [11]. Windows stores the search terms used by most applications. Therefore, when Regedit is used to delete registry entries, search datapertaining to these entries is saved and is easily recovered. Unlike Regedit, the shredder programs do not leave any such traces. The shredder programs examined in this work have certain limitations. The most serious limitation is the lack of user input. In particular, users cannot submit program names or terms that should be located and removed. For example, Entries 5 and 6 could easily have been deleted if the shredder programs allowed users to enter the specific entries they want erased from the registry Regedit addresses this issue by permitting manual deletion. Butthis is problematic because, as described above, Windows stores the search terms used to locate the registry entries. Ironically, attempting to delete entries creates additional entries that must be deleted. Finally, the shredder programs do not wipe all the data. As verified by our experiments, traces of emule remained even after it was uninstalled and the shredder programs were executed. 6. Conclusions Shredder programs are useful tools, but they are unable to erase all traces of potentially sensitive Windows Registry data. The manual deletion of data is an option, but the process of searching for the data to delete leaves traces. The burden, therefore, falls on the user to understand the nature and locations of the data that remain on a computer system. Short of wiping the entire hard drive, there is no way to remove all the sensitive data and references to its existence. Acknowledgements This research was supported by the Council for Scientific and Industrial Research of the Republic of South Africa. References [1] AccessData, FTK Imager, Lindon, Utah ( [2] AccessData, Registry quick find chart, Lindon, Utah ( data.com).
8 58 ADVANCES IN DIGITAL FORENSICS IV [3] AccessData, Registry Viewer, Lindon, Utah ( [4] AccessData, Ultimate Toolkit, Lindon, Utah ( [5] H. Berghel, and D. Hoelzer, Digital village: Disk wiping by any other name, Communications of the ACM, vol. 49(8), pp , [6] H. Carvey, Windows Forensics and Incident Recovery, Addison- Wesley, Boston, Massachusetts, [7] emule.org, emule ( [8] G. Francia and K. Clinton, Computer forensics laboratory and tools, Journal of Computing Sciences in Colleges, vol.20(6),pp , [9] S. Garfinkel and A. Shelat, Remembrance of data passed: A study of disk sanitization practices, IEEE Security and Privacy, vol. 1(1), pp , [10] W. Harrison, D. Aucsmith, G. Heuston, S. Mocas, M. Morrissey and S. Russelle, A lessons learned repository for computer forensics, International Journal of Digital Evidence, vol.1(3),2002. [11] N. Joukov, H. Papaxenopoulos and E. Zadok, Secure deletion myths, issues and solutions, Proceedings of the Second ACM Workshop on Storage Security and Survivability, pp.61 66,2006. [12] Microsoft Help and Support, Windows Registry information for advanced users, Microsoft Corporation, Redmond, Washington (support.microsoft.com/kb/256986). [13] Piriform, CCleaner ( [14] Right Utilities, Registry Washer (
Legal Notices. AccessData Corp.
Legal Notices AccessData Corp. makes no representations or warranties with respect to the contents or use of this documentation, and specifically disclaims any express or implied warranties of merchantability
Microsoft Vista: Serious Challenges for Digital Investigations
Proceedings of Student-Faculty Research Day, CSIS, Pace University, May 2 nd, 2008 Microsoft Vista: Serious Challenges for Digital Investigations Darren R. Hayes and Shareq Qureshi Seidenberg School of
Virtual CodeMeter Activation Guide
Virtual CodeMeter Activation Guide Introduction A Virtual CodeMeter (VCM) allows the user to run licensed AccessData products without a physical CodeMeter device. A VCM can be created using AccessData
Who is Reading the Data on Your Old Computer?
Who is Reading the Data on Your Old Computer? Vivienne Mee Rits Information Security Citywest Business Campus Co. Dublin [email protected] ABSTRACT Researchers at Rits Information Security performed
CONCEPT MAPPING FOR DIGITAL FORENSIC INVESTIGATIONS
Chapter 22 CONCEPT MAPPING FOR DIGITAL FORENSIC INVESTIGATIONS April Tanner and David Dampier Abstract Research in digital forensics has yet to focus on modeling case domain information involved in investigations.
Impact of Digital Forensics Training on Computer Incident Response Techniques
Impact of Digital Forensics Training on Computer Incident Response Techniques Valorie J. King, PhD Collegiate Associate Professor University of Maryland University College Presentation to AFCEA June 25,
Cloud Forensics. 175 Lakeside Ave, Room 300A Phone: 802/865-5744 Fax: 802/865-6446 http://www.lcdi.champlin.edu
Cloud Forensics Written & Researched by: Maegan Katz & Ryan Montelbano 175 Lakeside Ave, Room 300A Phone: 802/865-5744 Fax: 802/865-6446 http://www.lcdi.champlin.edu November 4, 2013 Disclaimer: This document
1! Registry. Windows System Artifacts. Understanding the Windows Registry. Organization of the Windows Registry. Windows Registry Viewer
1! Registry Understanding the Windows Registry! A database that stores hardware and software configuration information, network connections, user preferences, and setup information Windows System Artifacts
Technical Proposal on ATA Secure Erase Gordon Hughes+ and Tom Coughlin* +CMRR, University of California San Diego *Coughlin Associates
Technical Proposal on ATA Secure Erase Gordon Hughes+ and Tom Coughlin* +CMRR, University of California San Diego *Coughlin Associates Introduction and Summary Secure erase SE is defined in the ATA specification
COEN 152 / 252 Lab Exercise 1. Imaging, Hex Editors & File Types
COEN 152 / 252 Lab Exercise 1 Imaging, Hex Editors & File Types In this lab we will explore the concepts associated with creating a forensic image. Write-blocking will be accomplished utilizing a mounted
Digital Forensics. Tom Pigg Executive Director Tennessee CSEC
Digital Forensics Tom Pigg Executive Director Tennessee CSEC Definitions Digital forensics Involves obtaining and analyzing digital information as evidence in civil, criminal, or administrative cases Analyze
State of the art of Digital Forensic Techniques
State of the art of Digital Forensic Techniques Enos K. Mabuto 1, H. S Venter 2 Department of Computer Science University of Pretoria, Pretoria, 0002, South Africa Tel: +27 12 420 3654 Email: [email protected]
Microsoft Diagnostics and Recovery Toolset 7 Evaluation Guide
Microsoft Diagnostics and Recovery Toolset 7 Evaluation Guide White Paper Descriptor This document provides administrators with information and steps-by-step technique for deploying Microsoft Diagnostics
FORENSIC ANALYSIS OF WINDOWS REGISTRY AGAINST INTRUSION
FORENSIC ANALYSIS OF WINDOWS REGISTRY AGAINST INTRUSION Haoyang Xie 1, Keyu Jiang 1, Xiaohong Yuan 2 and Hongbiao Zeng 3 1 Department of Informatics, Fort Hays State University, Hays, KS, US [email protected]
Forensically Determining the Presence and Use of Virtual Machines in Windows 7
Forensically Determining the Presence and Use of Virtual Machines in Windows 7 Introduction Dustin Hurlbut Windows 7 has the ability to create and mount virtual machines based upon launching a single file.
ACTIVE DIRECTORY DEPLOYMENT
ACTIVE DIRECTORY DEPLOYMENT CASAS Technical Support 800.255.1036 2009 Comprehensive Adult Student Assessment Systems. All rights reserved. Version 031809 CONTENTS 1. INTRODUCTION... 1 1.1 LAN PREREQUISITES...
A+ Guide to Software: Managing, Maintaining, and Troubleshooting, 5e. Chapter 3 Installing Windows
: Managing, Maintaining, and Troubleshooting, 5e Chapter 3 Installing Windows Objectives How to plan a Windows installation How to install Windows Vista How to install Windows XP How to install Windows
Digital Forensics. Module 4 CS 996
Digital Forensics Module 4 CS 996 Hard Drive Forensics Acquisition Bit for bit copy Write protect the evidence media EnCase for DOS Safeback (NTI: www.forensics-intl.com) Analysis EnCase FTK (www.accessdata.com)
Deploying EFS: Part 2
Deploying EFS: Part 2 John Morello You can think of any Encrypting File System (EFS) deployment as having essentially two parts: the back-end design portion focusing on certificate management and recovery
Contents 1. Introduction 2. Security Considerations 3. Installation 4. Configuration 5. Uninstallation 6. Automated Bulk Enrollment 7.
Contents 1. Introduction 2. Security Considerations 3. Installation 4. Configuration 5. Uninstallation 6. Automated Bulk Enrollment 7. Troubleshooting Introduction Adaxes Self-Service Client provides secure
Fall. Forensic Examination of Encrypted Systems Matthew Postinger COSC 374
Fall 2011 Forensic Examination of Encrypted Systems Matthew Postinger COSC 374 Table of Contents Abstract... 3 File System Encryption... 3 Windows EFS... 3 Apple FileVault... 4 Full Disk Encryption...
MaxSea TZ: Microsoft SQL Server problems End User
MaxSea TZ: Microsoft SQL Server problems End User This TechNote applies to MaxSea TimeZero Navigator and Explorer v1.9.5 and above Description: TimeZero uses Microsoft SQL server to manage routes, marks,
LAVASOFT FILE SHREDDER FILE SHREDDER
LAVASOFT FILE SHREDDER FILE SHREDDER SOFTWARE MANUAL Table of Contents Install and Uninstall 1 Install Using a CD 1 Install Using a File 1 Uninstall the Application 1 Activation 2 What is the Subscription
PRIVAZER USER GUIDE Version 1.2 Dated 08 June 2013
PRIVAZER USER GUIDE Version 1.2 Dated 08 June 2013 CONTENTS Introduction... 3 System Requirements... 4 Install PrivaZer... 5 Uninstall PrivaZer... 9 Scan and Clean C Drive... 11 Scan Options... 20 Cleanup
RECOVERING DELETED DATA FROM FAT PARTITIONS WITHIN MOBILE PHONE HANDSETS USING TRADITIONAL IMAGING TECHNIQUES
RECOVERING DELETED DATA FROM FAT PARTITIONS WITHIN MOBILE PHONE HANDSETS USING TRADITIONAL IMAGING TECHNIQUES KEVIN MANSELL CONTROL-F LTD. [email protected] DARREN LOLE & FIONA LITCHFIELD SERVICE
Digital Forensic. A newsletter for IT Professionals. I. Background of Digital Forensic. Definition of Digital Forensic
I Digital Forensic A newsletter for IT Professionals Education Sector Updates Issue 10 I. Background of Digital Forensic Definition of Digital Forensic Digital forensic involves the collection and analysis
ACE STUDY GUIDE. 3. Which Imager pane shows information specific to file systems such as HFS+, NTFS, and Ext2? - Properties Pane
ACE STUDY GUIDE *Note* All of the actual exam questions are in multiple choice format. This Study Guide is designed to cover all of the material on the exam, 1. FTK Imager supports the encryption of forensic
Table of Contents. Cisco Disabling ICS when Preparing to Install or Upgrade to Cisco VPN Client 3.5.X on Microsoft Windows XP
when Preparing to Install or Upgrade to Cisco VPN Client 3.5.X s XP Table of Contents Disabling ICS when Preparing to Install or Upgrade to Cisco VPN Client 3.5.X...1 Introduction...1 Before You Begin...1
GOOGLE DESKTOP FORENSICS WIN!
The Quarterly Magazine for Digital Forensics Practitioners WIN! A STEGALYZER USB FROM SARC ISSUE 15 MAY 2013 INSIDE / Cryptographic Key Recovery / Tunnelling Out: Data Extraction / Fuzzing Risks in Software
RecoverIt Frequently Asked Questions
RecoverIt Frequently Asked Questions Windows Recovery FAQs When can I use Windows Recovery application? This application is used to recover the deleted files from internal or external storage devices with
LexisNexis CaseMap-WorkSite Plug-In ReadMe
LexisNexis CaseMap-WorkSite Plug-In ReadMe Version Number 2.0 (Build 1) ReadMe updated March 27, 2007 CONTENTS 1. System Requirements 2. Installing CaseMap-WorkSite Plug-In 3. Uninstalling CaseMap-WorkSite
Developing Computer Forensics Solutions for Terabyte Investigations
Developing Computer Forensics Solutions for Terabyte Investigations Eric Thompson Corporation Orem, Utah USA www.accessdata.com Overview Computer Forensic Definition, Objectives and Policies History of
STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER
Notes: STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER 1. These instructions focus on installation on Windows Terminal Server (WTS), but are applicable
Digital Forensics Tutorials Acquiring an Image with FTK Imager
Digital Forensics Tutorials Acquiring an Image with FTK Imager Explanation Section Digital Forensics Definition The use of scientifically derived and proven methods toward the preservation, collection,
Windows 7: Current Events in the World of Windows Forensics
Windows 7: Current Events in the World of Windows Forensics Troy Larson Senior Forensic Program Manager Network Security, Microsoft Corp. Where Are We Now? Vista & Windows 2008 BitLocker. Format-Wipes
Determining VHD s in Windows 7 Dustin Hurlbut
Introduction Windows 7 has the ability to create and mount virtual machines based upon launching a single file. The Virtual Hard Disk (VHD) format permits creation of virtual drives that can be used for
How to Uninstall Manually and Upgrade the Cisco VPN Client 3.5 and Later for Windows 2000, Windows XP and Windows Vista
How to Uninstall Manually and Upgrade the Cisco VPN Client 3.5 and Later for Windows 2000, Windows XP and Windows Vista Document ID: 18840 Introduction Prerequisites Requirements Components Used Conventions
Nobeltec TZ: Microsoft SQL Server problems
Nobeltec TZ: Microsoft SQL Server problems Description: TimeZero uses Microsoft SQL server to manage routes, marks, logbook and track data. Microsoft SQL server is installed as part of the TimeZero installation.
VMware Mirage Web Manager Guide
Mirage 5.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of this document,
A Practical Approach for Evidence Gathering in Windows Environment
A Practical Approach for Evidence Gathering in Windows Environment Kaveesh Dashora Department of Computer Science & Engineering Maulana Azad National Institute of Technology Bhopal, India Deepak Singh
IFSM 310 Software and Hardware Concepts. A+ OS Domain 2.0. A+ Demo. Installing Windows XP. Installation, Configuration, and Upgrading.
IFSM 310 Software and Hardware Concepts "You have to be a real stud hombre cybermuffin to handle 'Windows'" - Dave Barry Topics A+ Demo: Windows XP A+ OS Domain 2.0 Chapter 12: File and Secondary Storage
Analysis of Evidence in Cloud Storage Client Applications on the Windows Platform
Int'l Conf. Security and Management SAM'15 3 Analysis of Evidence in Cloud Storage Client Applications on the Windows Platform R. Malik 1, N. Shashidhar 1, and L. Chen 2 1 Department of Computer Science,
TZWorks Windows Event Log Viewer (evtx_view) Users Guide
TZWorks Windows Event Log Viewer (evtx_view) Users Guide Abstract evtx_view is a standalone, GUI tool used to extract and parse Event Logs and display their internals. The tool allows one to export all
Cloud Attached Storage
CTERA Appliance Disaster Recovery Guide Cloud Attached Storage June 2013 Version 3.2 1 Introduction This document is intended for CTERA Portal administrators. It describes how to replace CTERA appliances
Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background
Xerox Multifunction Devices Customer Tips June 5, 2007 This document applies to these Xerox products: X WC Pro 232/238/245/ 255/265/275 for the user Xerox Network Scanning HTTP/HTTPS Configuration using
Polar Help Desk Installation Guide
Polar Help Desk Installation Guide Copyright (legal information) Copyright Polar 1995-2005. All rights reserved. The information contained in this document is proprietary to Polar and may not be used or
airbackup installation and AdmiCash backup
airbackup installation and AdmiCash backup airbackup airbackup is an elegant solution for an external and safe backup of your system. The software provides various functions for the backup and restoration
NETWRIX WINDOWS SERVER CHANGE REPORTER
NETWRIX WINDOWS SERVER CHANGE REPORTER INSTALLATION AND CONFIGURATION GUIDE Product Version: 4.0 March 2013. Legal Notice The information in this publication is furnished for information use only, and
NetWrix Server Configuration Monitor
NetWrix Server Configuration Monitor Version 2.2 Quick Start Guide Contents NetWrix Server Configuration Monitor Quick Start Guide 1. INTRODUCTION... 3 1.1 KEY FEATURES... 3 1.2 LICENSING... 4 1.3 HOW
Hard drives dumped; information isn't DON'T BE SMUG IN THINKING PERSONAL DATA HAS BEEN ERASED By Larry Magid Special to the Mercury News
Erase Your Hard Drive Permanently erase files, emails, & Data from hard drive. Guaranteed! O&O DiskRecovery V3.0 Data Recovery for Windows with DeepScan function - Free Trial Delete porn history files
GFI White Paper PCI-DSS compliance and GFI Software products
White Paper PCI-DSS compliance and Software products The Payment Card Industry Data Standard () compliance is a set of specific security standards developed by the payment brands* to help promote the adoption
Advanced Registry Forensics with Registry Decoder. Dr. Vico Marziale Sleuth Kit and Open Source Digital Forensics Conference 2012 10/03/2012
Advanced Registry Forensics with Registry Decoder Dr. Vico Marziale Sleuth Kit and Open Source Digital Forensics Conference 2012 10/03/2012 Who am I? Senior Security Researcher @ DFS Published Researcher
Pcounter Web Report 3.x Installation Guide - v2014-11-30. Pcounter Web Report Installation Guide Version 3.4
Pcounter Web Report 3.x Installation Guide - v2014-11-30 Pcounter Web Report Installation Guide Version 3.4 Table of Contents Table of Contents... 2 Installation Overview... 3 Installation Prerequisites
Last modified: September 12, 2013 This manual was updated for TeamDrive Personal Server version 1.1.058
Last modified: September 12, 2013 This manual was updated for TeamDrive Personal Server version 1.1.058 2013 TeamDrive Systems GmbH Page 1 Table of Contents 1 Installing the TeamDrive Personal Server...
Forensics on the Windows Platform, Part Two
1 of 5 9/27/2006 3:52 PM Forensics on the Windows Platform, Part Two Jamie Morris 2003-02-11 Introduction This is the second of a two-part series of articles discussing the use of computer forensics in
Expunge REMOVING WINDOWS LOGIN TRACES CHAPTER. Exploit Techniques THE HACK DISSECTED
CHAPTER Expunge 5 Expunging is the process of destroying information to cover the tracks of the attacker. These steps allow a computer user to remove traces of their activity from a computer so that someone
Jetico Central Manager. Administrator Guide
Jetico Central Manager Administrator Guide Introduction Deployment, updating and control of client software can be a time consuming and expensive task for companies and organizations because of the number
How to Uninstall Manually and Upgrade the Cisco VPN Client 3.5 and Later for Windows 2000 and Windows XP
How to Uninstall Manually and Upgrade the Cisco VPN Client 3.5 and Later for Windows 2000 and Windows XP Document ID: 18840 Introduction Prerequisites Requirements Components Used Conventions Manually
A White Paper from AccessData Group. Cerberus. Malware Triage and Analysis
A White Paper from AccessData Group Cerberus Malware Triage and Analysis What is Cerberus? Cerberus is the first-ever automated reverse engineering tool designed to show a security analyst precisely what
PUBLIC Password Manager for SAP Single Sign-On Implementation Guide
SAP Single Sign-On 2.0 SP1 Document Version: 1.0 2015-10-02 PUBLIC Password Manager for SAP Single Sign-On Implementation Guide Content 1 Password Manager....4 2 Password Manager Installation Guide....5
A Short Introduction to Digital and File System Forensics
Antonio Barili Lab Dept. of Industrial and Information Engineering University of Pavia (Italy) [email protected] Every contact leaves a trace Culprit Scene Victim Edmond Locard (1877-1966) 2015 -
Manage the Endpoints. Palo Alto Networks. Advanced Endpoint Protection Administrator s Guide Version 3.1. Copyright 2007-2015 Palo Alto Networks
Manage the Endpoints Palo Alto Networks Advanced Endpoint Protection Administrator s Guide Version 3.1 Contact Information Corporate Headquarters: Palo Alto Networks 4401 Great America Parkway Santa Clara,
MICROSOFT STEP BY STEP INTERACTIVE VERSION 3.0 ADMINISTRATION GUIDE
MICROSOFT STEP BY STEP INTERACTIVE VERSION 3.0 ADMINISTRATION GUIDE Part 1: Network Installation Guide Introduction Part 1 of this document provides instructions for installing Microsoft Interactive Training
COMPUTER FORENSICS (EFFECTIVE 2013-14) ACTIVITY/COURSE CODE: 5374 (COURSE WILL BE LISTED IN THE 2013-14 CATE STUDENT REPORTING PROCEDURES MANUAL)
COMPUTER FORENSICS (EFFECTIVE 2013-14) ACTIVITY/COURSE CODE: 5374 (COURSE WILL BE LISTED IN THE 2013-14 CATE STUDENT REPORTING PROCEDURES MANUAL) COURSE DESCRIPTION: Computer Forensics is focused on teaching
Table of Contents. TPM Configuration Procedure... 2. 1. Configuring the System BIOS... 2
Table of Contents TPM Configuration Procedure... 2 1. Configuring the System BIOS... 2 2. Installing the Infineon TPM Driver and the GIGABYTE Ultra TPM Utility... 3 3. Initializing the TPM Chip... 4 3.1.
Upgrading from MSDE to SQL Server 2005 Express Edition with Advanced Services SP2
Upgrading from MSDE to SQL Server 2005 Express Edition with Advanced Services SP2 Installation and Configuration Introduction This document will walk you step by step in removing MSDE and the setup and
SEER Enterprise Shared Database Administrator s Guide
SEER Enterprise Shared Database Administrator s Guide SEER for Software Release 8.2 SEER for IT Release 2.2 SEER for Hardware Release 7.3 March 2016 Galorath Incorporated Proprietary 1. INTRODUCTION...
RECOVERING FROM SHAMOON
Executive Summary Fidelis Threat Advisory #1007 RECOVERING FROM SHAMOON November 1, 2012 Document Status: FINAL Last Revised: 2012-11-01 The Shamoon malware has received considerable coverage in the past
HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION
HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION Version 1.1 / Last updated November 2012 INTRODUCTION The Cloud Link for Windows client software is packaged as an MSI (Microsoft Installer)
MCTS Guide to Microsoft Windows 7. Chapter 7 Windows 7 Security Features
MCTS Guide to Microsoft Windows 7 Chapter 7 Windows 7 Security Features Objectives Describe Windows 7 Security Improvements Use the local security policy to secure Windows 7 Enable auditing to record security
PORTAL ADMINISTRATION
1 Portal Administration User s Guide PORTAL ADMINISTRATION GUIDE Page 1 2 Portal Administration User s Guide Table of Contents Introduction...5 Core Portal Framework Concepts...5 Key Items...5 Layouts...5
Version: 1.5 2014 Page 1 of 5
Version: 1.5 2014 Page 1 of 5 1.0 Overview A backup policy is similar to an insurance policy it provides the last line of defense against data loss and is sometimes the only way to recover from a hardware
Avira System Speedup Release Information
Release Information Avira System Speedup is a new PC optimization and error repair utility that improves the performance of your PC. Regularly cleaning your computer could save you costly maintenance fees.
Selected Windows XP Troubleshooting Guide
1 Selected Windows XP Troubleshooting Guide To locate lost files: Compiled by: Jason M. Cohen Check these locations to locate lost files: The My Documents folder Click Start, and then click My Documents.
CA DLP. Stored Data Integration Guide. Release 14.0. 3rd Edition
CA DLP Stored Data Integration Guide Release 14.0 3rd Edition This Documentation, which includes embedded help systems and electronically distributed materials, (hereinafter referred to as the Documentation
Avira System Speedup. HowTo
Avira System Speedup HowTo Table of Contents 1. Introduction... 4 1.1 What is Avira System Speedup?...4 2. Installation... 5 2.1 System Requirements...5 2.2 Installation...5 3. Using the program... 8 3.1
Installing, Uninstalling, and Upgrading Service Monitor
CHAPTER 2 Installing, Uninstalling, and Upgrading Service Monitor This section contains the following topics: Preparing to Install Service Monitor, page 2-1 Installing Cisco Unified Service Monitor, page
HP ProtectTools Embedded Security Guide
HP ProtectTools Embedded Security Guide Document Part Number: 364876-001 May 2004 This guide provides instructions for using the software that allows you to configure settings for the HP ProtectTools Embedded
ReportByEmail ODBC Connection setup
ReportByEmail ODBC Connection setup Page 2 of 28 Content Introduction... 3 ReportByEmail Server and changing ODBC settings... 3 Microsoft AD Windows setup... 3 Important notice regarding 32-bit / 64-bit
Education Software Installer 2011
Education Software Installer 2011 Windows operating systems System administrator s guide Trademark notice SMART Notebook, SMART Document Camera, SMART Response, SMART Sync, SMART Classroom Suite, Senteo,
Lesson Plans Microsoft s Managing and Maintaining a Microsoft Windows Server 2003 Environment
Lesson Plans Microsoft s Managing and Maintaining a Microsoft Windows Server 2003 Environment (Exam 70-290) Table of Contents Table of Contents... 1 Course Overview... 2 Section 0-1: Introduction... 4
High Availability Setup Guide
High Availability Setup Guide Version: 9.0 Released: March 2015 Companion Guides: The UniPrint Infinity Administrator s Guide, Cluster Guide and Mobile Setup Guide can be found online for your convenience
Windows Administration Terminal Services, AD and the Windows Registry. INLS 576 Spring 2011 Tuesday, February 24, 2011
Windows Administration Terminal Services, AD and the Windows Registry INLS 576 Spring 2011 Tuesday, February 24, 2011 Terminal Services Uses RDP (Remote Desktop Protocol), relies on TCP/IP, and falls under
Issue Tracking Anywhere Installation Guide
TM Issue Tracking Anywhere Installation Guide The leading developer of version control and issue tracking software Table of Contents Introduction...3 Installation Guide...3 Installation Prerequisites...3
Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit www.specopssoft.
. All right reserved. For more information about Specops Inventory and other Specops products, visit www.specopssoft.com Copyright and Trademarks Specops Inventory is a trademark owned by Specops Software.
Corrupt and Shutdown Dirty EVTX Log Files: A Comparison of Recovery Using the Microsoft Event Viewer Versus Ipswitch's LogHealer Technology
Corrupt and Shutdown Dirty EVTX Log Files: A Comparison of Recovery Using the Microsoft Event Viewer Versus Ipswitch's LogHealer Technology As the Microsoft Windows Vista, Windows Server 2008, and Windows
International Journal of Advance Research in Computer Science and Management Studies
Volume 3, Issue 2, February 2015 ISSN: 2321 7782 (Online) International Journal of Advance Research in Computer Science and Management Studies Research Article / Survey Paper / Case Study Available online
Events Forensic Tools for Microsoft Windows
Events Forensic Tools for Microsoft Windows Professional forensic tools Events Forensic Tools for Windows Easy Events Log Management Events Forensic Tools (EFT) is a fast, easy to use and very effective
Computer Anti-forensics Methods and Their Impact on Computer Forensic Investigation
Computer Anti-forensics Methods and Their Impact on Computer Forensic Investigation Przemyslaw Pajek and Elias Pimenidis School of Computing IT and Engineering, University of East London, United Kingdom
Certified Digital Forensics Examiner
Cyber Security Training & Consulting Certified Digital COURSE OVERVIEW 5 Days 40 CPE Credits $3,000 Digital is the investigation and recovery of data contained in digital devices. This data is often the
SystemTech AntiSpyware Manual
Summitsoft Corporation SystemTech AntiSpyware Manual This guide is distributed with software that includes an end user agreement, this guide, as well as the software described in it, is furnished under
