Computer Forensic Analysis in a Virtual Environment
|
|
|
- Gloria Welch
- 10 years ago
- Views:
Transcription
1 Computer Forensic Analysis in a Virtual Environment Derek Bem Ewa Huebner University of Western Sydney, Australia Abstract In this paper we discuss the potential role of virtual environments in the analysis phase of computer forensics investigations. General concepts of virtual environments and software tools are presented and discussed. Further we identify the limitations of virtual environments leading to the conclusion that this method can not be considered to be a replacement for conventional techniques of computer evidence collection and analysis. We propose a new approach where two environments, conventional and virtual, are used independently. Further we demonstrate that this approach can considerably shorten the time of the computer forensics investigation analysis phase and it also allows for better utilisation of less qualified personnel. Keywords: Computer Forensics, Virtual Machine, computer evidence. Introduction In this paper we examine the application of the VMWare (VMWare, 2007) virtual environment in the analysis phase of a computer forensics investigation. We show that the environment created by VMWare differs considerably from the original computer system, and because of that VMWare by itself is very unlikely to produce court admissible evidence. We propose a new approach when two environments, conventional and virtual, are used concurrently and independently. After the images are collected in a forensically sound way, two copies are produced. One copy is protected using the strict chain of custody rules, and the other is given to a technician who works with it in a virtual machine environment not constrained by formal forensics procedures. Any findings are documented and passed to a more qualified person who confirms them in accordance with forensics rules. An additional advantage is that the virtual machine environment makes it easy to demonstrate the findings to a non-technical audience. An example scenario is described to illustrate our approach. We took a small Windows XP system, created a forensic image of its hard disk, and demonstrated the advantages of using two environments. The example shows that the correct application of a virtual environment approach results in a less time spent on analysing the evidence, giving more chance of discovering important data, and allowing less qualified personnel to be involved in a more productive way. We decided to use only free and readily available utilities to allow everyone to repeat our experiment, and to encourage the reader to try experimenting with their own cases.
2 What is a Virtual Machine Virtual machine (also known as VM ) is a software product which allows the user to create one or more separate environments, each simulating its own set of hardware (CPU, hard disk, memory, network controllers, and other components) and its own software. Ideally each virtual machine should behave like a fully independent computer with its own operating system and its own hardware. The user can control each environment independently and, if required, network virtual computers together or connect them to an external physical network. While this approach is powerful and flexible, it requires a lot of additional resources, because each virtual computer uses real hardware components present in the computer it runs on. It should also be noted that virtual machine software is complex, and many compromises and restrictions are to be expected. Anyone attempting to use it should have a good understanding of what can and cannot be achieved. Virtualisation is an old concept, first introduced in the 1960s with the appearance of mainframe computers. It was re-introduced to personal computers in the 1990s, and currently major products available are: Microsoft Virtual PC (Microsoft Virtual PC 2007), VMWare software tools range (VMWare, 2007), an open source (free) software QEMU (Bellard, 2007), and a few others. Computer Forensics And Virtual Machine Environments The conventional computer forensics process comprises a number of steps, and it can be broadly encapsulated in four key phases (Kruse II & Heiser, 2002): Access Acquire Analyse (the focus of this paper) Report During the acquire phase an investigator captures as much live system volatile data as possible, powers down the system, and later creates a forensic (bit by bit) image of all storage devices (Brown, 2005). An image of a storage device is typically acquired using one of many dd based tools (Nelson, Phillips, Enfinger, & Steuart, 2006). This image is stored in the dd format (Rude, 2000), or a proprietary format typically based on dd (Bunting & Wei, 2006). The image is an identical copy of the original disk. It should be noted, however, that the old rule where the image of a hard disk was assumed to be identical with the original hard disk does not necessary apply today. There are many proprietary formats commonly used today which are arguably not identical with the original hard disk; they may include additional metadata like the investigator s name, notes, or hash values. An example of proprietary format is a recently developed and becoming increasingly popular Advanced Forensic Format (AFF) (Garfinkel, 2005). The AFF goes even further by segmenting the original image where each segment has a header, a name, a 32-bit argument, an optional data payload, and finally a tail. The relevance of this short image format overview is the realisation that computer specialist findings may also 2
3 be based on examining an image which is in some ways changed, and is not identical with the original. Because the dd image is the same as the original, it could be copied to the same or a larger hard disk, and booted on another computer system. Such an approach is impractical in recreating the original environment due to too many possible hardware combinations. If the image is booted on a machine with a different hardware configuration, the operating system would discover these differences, and attempt (in some cases unsuccessfully) to install the missing drivers. Furthermore some installed services and software products may refuse to start, or the system could fail to boot at all. Similar issues exist in a VM environment. VM simulates only some basic hardware components; it is not created to provide full support for a wide range of hardware devices. The acquired dd image can not be immediately booted in a VM environment, as VM requires additional files containing information about the environment being booted. Various software tools can solve this problem by creating the additional files with the parameters required by VM. Some of these utilities are: EnCase Physical Disk Emulator (PDE), commercial product (EnCase Forensic Modules, 2007), ProDiscover family of commercial and free computer security tools from Technology Pathways, LLC (ProDiscover, 2007) Live View, free utility offered under Gnu Public License (GPL) (Live View, 2007) There were some attempts made to use the VM environment for computer forensics data analysis (ebaca, 2006), but it appears that the suitability of the findings obtained this way as evidence in a court of law is questionable. Some investigators concluded rather prematurely that VMWare has no real value as a forensic tool (Fogie, 2004). There are many changes to the original environment required to enable the image to boot in the VM environment, and once the system is booted new data will be written to the original image thus modifying it. An image which is known to be considerably changed would be immediately challenged in a court of law as flawed. A computer expert could argue that the changes were not relevant to the evidence being presented, however it is unlikely that such a line of argument would be accepted by the court. The golden rule Create a bit-wise copy of the evidence in a backup destination, ensuring that the original data is write-protected. Subsequent data analysis should be performed on this copy and not on the original evidence is undeniably broken in the virtual environment. The Proposed Parallel Approach Each of the four phases of the computer forensics process mentioned in the previous section is further divided into specific steps, and each has to follow strict procedures. The Australian Institute of Criminology guide (McKemmish,1999) recommends that the process of analyzing computer evidence should comply with the following basic rules: 3
4 Minimal handling of the original. Account for any change. Comply with the rules of evidence. Do not exceed your knowledge. There is no commonly accepted computer forensic certification, but it is expected that a person conducting an analysis and presenting the report in the court is an expert (Meyers & Rogers, 2004) who possesses relevant specialised knowledge. We propose that the accuracy of the process can be considerably improved, and the total time required to analyse the data can be shortened if the process is expanded to include two parallel investigative streams, as shown in figure 1. In our model we used two levels of computer forensics personnel: less experienced and more experienced, respectively referred to as Computer Technician and Professional Investigator. This is similar to the roles CNF Technician (Computer and Network Forensic Technician) and CNF Professional (Computer and Network Forensic Professional) in classification proposed by Yasinsac et al (Yasinsac, Erbacher, Marks, Pollitt, & Sommer, 2003). Modus operandi of such a team is as follows: Fully trained and more experienced Professional Investigator adheres strictly to computer forensics investigation methods. Less qualified Computer Technician does not have to strictly follow forensic rules, and never has any direct input to the formal reporting process. The role of the Computer Technician is to check the copy of the materials for anything of potential interest and then report the findings to the Professional Investigator. Access Acquire Analyse Report Professional Investigator Master image Computer Technician VM environment: copy of master image, similar to the original Figure 1: Dual Data Analysis Process In the analysis phase of the computer forensics investigation a copy of the acquired image is given to the Computer Technician. Their task is to boot the image in a 4
5 virtual machine environment, treat it as a normal, live system, and search for all details relevant to the investigation. The methodology used by the Computer Technician invalidates the integrity of the acquired image, but this is of no consequence to the investigation. All findings are passed to the Professional Investigator, who then uses proper computer forensics techniques to confirm the findings, and to make further data searches, if necessary. The findings of the Computer Technician are never included directly in the reporting process. The final report is created by the Professional Investigator, and it only includes the findings confirmed by proper forensic analysis. As we will demonstrate in the following simple example scenario, using the virtual machine environment in tandem with the cooperation between the Computer Technician and the Professional Investigator can deliver better results faster. The Example Scenario A powered off personal computer was found when the premises of a person suspected of illegal drug trafficking were searched. A computer forensics investigator was requested to assist in the case. The search warrant provided legal authority, and the investigator was asked to check the computer and find all information pertaining to drug trafficking, including details of financial transactions and any relevant letters or documents. The investigator documented the personal computer s hardware configuration, and acquired the hard disk image using the dd utility from the HELIX bootable forensic CD (E-fense, 2007). SHA-1 and MD5 hash values and relevant case details were recorded, and the chain of custody was created according to local forensic procedures (Hart, April 2004). Two copies of the image named hda1- img3.dd were given to two people in the forensic lab: the Professional Investigator, who updated the chain of custody document and locked the image in a safe place, the Computer Technician, who updated the chain of custody corresponding to the second image, and also locked the image in a safe place. The Computer Technician was asked to boot the image in a VM environment, and to use any suitable tools to search the booted system. To facilitate this VMWare Server (VMWare Server, 2007), a free virtualisation product from VMWare, was installed on a separate computer. As expected, the image hda1-img3.dd could not be directly booted in the VM environment. The Computer Technician used Live View software, see figure 2, to create additional files needed to boot the image in VM. The Live View proved to be simple to use and reliable, but any other software with the same functionality could also be used. The Live View messages window creates a comprehensive activity log, which was copied by the Computer Technician and included in the notes. After Live View finished creating files, it automatically offered to boot the image in VMWare. 5
6 Figure 2: Live View Window The first boot of hda1-img3.dd image in the VMWare Server produced a series of found new hardware messages. This was expected, as VMWare simulates different hardware than the hardware of the original Windows XP installation. New devices were identified and installed; all required drivers were common, as they were a part of the standard Windows distribution, and were quickly installed without the need to provide propriety software. 6
7 Figure 3: VMWare Server Window After the first successful boot of the system the Computer Technician powered the VM machine off, and installed VMWare tools which improve mouse operation and provide a higher VM screen resolution (see the message You do not have VMWare Tools installed in left hand bottom corner in figure 3). Before booting the system again the Computer Technician checked the virtual machine settings shown in figure 4, and noted that only four devices were installed: memory, hard disk, CD-ROM and the USB controller. Other devices available to the virtual machine were seen in the Add Hardware Wizard, but they were of no immediate interest. The Ethernet controller was not installed, thus the virtual machine was isolated from any networks and the Internet. 7
8 Figure 4: Virtual Machine Settings Each time the system was booted the Computer Technician observed the panel which started automatically and indicated an attempt to log on to DriveHQ, as shown in figure 5. These attempts failed, as there was no Internet connection from this virtual machine. Figure 5: DriveHQ Log On Window The Computer Technician checked the Internet from another computer, and found that the DriveHQ ("Drive Headquarters", 2007) is an Internet virtual storage service which allows a user to store a large volume of any data. To access the DriveHQ account a user name and password were required. The user name kugel was visible in the log on panel, but the password was hidden behind a row of dots. In order to find out what the password was the Computer Technician decided to install in the virtual machine additional software called password revealer. There are many password revealing tools, and they have different capabilities; in this case some of them failed to reveal the password. Finally a tool named Aqua Deskperience succeeded (Aqua Deskperience, 2007): the password was just555me (see figure 6). 8
9 Figure 6: Aqua Deskperience Reveals Drivehq Account Password The Computer Technician continued the examination of the booted system using standard Windows tools. Windows Explorer did not show any folders or files of relevance to the case being investigated. Web browser bookmarks also did not point to any Web sites which could be relevant. The Computer Technician then checked what additional software was installed on the investigated system, and discovered on the desktop an icon for the Simple File Shredder (Simple File Shredder, 2006) (see figure 7). A quick Internet check showed that the Simple File Shredder is a utility that securely deletes files, making their recovery impossible. Figure 7: Desktop icons Two important points are worth noting here: 1. The image of the disk used to run the system is no longer identical with the image hda1-img3.dd acquired using forensically sound methods. We installed various new device drivers and new software packages (Aqua Deskperience, possibly a few others as well). Various files and folders were touched by checking them in Windows Explorer, and by opening them in their native applications. It would be unrealistic to argue that the image is still valid as evidence; it is now contaminated. 2. The original acquired image hda1-img3.dd is still kept in custody by the Professional Investigator; it is unchanged and forensically valid. 9
10 The Computer Technician reported to the Professional Investigator the following basic findings: It is likely that there are not many traces of any files of interest to the investigation, as the person using the computer installed a secure deletion tool. It is possible that all such files have been irrecoverably erased. It is likely that materials of evidentiary value were not kept on the computer, as the owner had a virtual Internet storage account which allowed them to keep all data on a remote server. It was possible to recover the user name and password to the remote storage system account. Using this information the Professional Investigator can now confirm all the findings using forensically sound methodology and proper forensics software tools. The remote account on DriveHQ can be accessed from another computer, and all files stored there copied and examined. The hda1-img3.dd disk image can still be analysed with computer forensics software for any traces of unshredded files with the knowledge that the likelihood of finding anything of value is small and a large amounts of time should not be dedicated to this task. Conclusion The simple scenario presented above demonstrates that the cooperation between two teams equipped with different sets of tools, and using personnel with different levels of expertise, can produce much faster results, and will lessen the workload of highly qualified Professional Investigators. The Professional Investigator using proper computer forensics tools and techniques would most likely achieve the same results working in a conventional setup, without using a virtual environment and without the help of a Computer Technician. However the described method of using two environments, conventional and virtual, could save time and increase the chances of finding important evidence. If only conventional image analysing techniques were used in the presented example scenario, considerable skills and significantly more time would be required to find the DriveHQ account, the user name and password. The same information was in plain view when the Computer Technician booted the investigated image in VMWare, and the technician used commonly available tools (e.g. the password revealer) to search the investigated system. It was then considerably easier for the Professional Investigator to benefit from the initial findings, and to conduct a forensically sound and properly documented search on the image. An additional advantage for an organization is that technical personnel can be exposed to computer forensics techniques in stages, without compromising real evidence, yet at the same time providing genuinely valuable input to the process. This approach can be also seen as a part of an internal training process, where a person with little computer forensics experience, but good technical knowledge, is not immediately given the responsibilities of a Professional Investigator, but is first introduced to the forensic process by conducting investigations in a virtual environment. 10
11 In this paper we described the process of using conventional and virtual environments in the analysis phase of computer forensics investigations. We also proposed the ground rules for cooperation between the Computer Technician and the Professional Investigator. We believe that future research is needed to better formalise the whole process, with emphasis on what is expected from the Computer Technician. Future research in the area is also required to more thoroughly test other available virtualisation software tools, and to find their strengths and weaknesses. Copyright 2007 International Journal of Digital Evidence About the Authors Derek Bem, MElecEng Warsaw, MIEAust, CPEng ) is a Lecturer in the School of Computing and Mathematics at University of Western Sydney, Australia. Derek has extensive experience in the computer industry, where he worked in IBM and other companies as a hardware and software engineer. Derek is currently coordinating UWS teaching in the Computer Forensics area. Ewa Huebner, MElecEng Warsaw, PhD Sydney, MACS ([email protected] ) is a Senior Lecturer in the School of Computing and Mathematics at University of Western Sydney, Australia. Ewa has extensive experience teaching computer science subjects, and she is currently leading the UWS Computer Forensics research group. UWS computer forensics web site can be found at
12 References Deskperience. (2007). Aqua Deskperience. Retrieved 20 January 2007, from Bellard, Fabrice. (2007). QEMU. Retrieved January 17, 2007, from Brown, C. L. T. (2005). Computer Evidence: Collection & Preservation. Hingham, MA: Charles River Media. Bunting, S., & Wei, W. (2006). EnCase Computer Forensics: The Official EnCE: EnCase Certified Examiner Study Guide (1st ed.). Indianapolis, IN: Wiley Publishing. CERT, Software Engineering Institute. (2007). Live View. Retrieved February 12, 2007, from Drive Headquarters. (2007). Retrieved 2 November 2006, 2 November 2006, from ebaca. (2006). Penguin Sleuth Kit Virtual Computer Forensics and Security Platform. Retrieved 28 November 2006 from E-fense. (2007). The HELIX Live CD Page. Retrieved 9 February 2007, from Fogie, S. (2004). VOOM vs The Virus (CIH). Retrieved 12 March 2005 from Garfinkel, S. (2005). The Advanced Forensic Format 1.0. Retrieved November 13, 2006 from Guidance Software. (2007). EnCase Forensic Modules. Retrieved January 25, 2007, from Hart, S. V. (April 2004). Forensic Examination of Digital Evidence: A Guide for Law Enforcement. from Kruse II, W. G., & Heiser, J. G. (2002). Computer Forensics: Incident Response Essentials (1st ed.): Addison Wesley Professional. McKemmish, R. (1999). What is Forensic Computing? : Australian Institute of Criminology. Meyers, M., & Rogers, M. (2004). Computer Forensics: The Need for Standardization and Certification. International Journal of Digital Evidence, 3(2). 12
13 Microsoft. Microsoft Virtual PC Retrieved 22 February 2007, from Nelson, B., Phillips, A., Enfinger, F., & Steuart, C. (2006). Guide to Computer Forensics and Investigations, Second Edition (2nd ed.). Boston, MA: Thomson Course Technology. Rude, T. (2000). DD and Computer Forensics. Retrieved October 23, 2003 from scar5 Software. (2006). Simple File Shredder. Retrieved 15 December 2006, from Technology Pathways, LLC. (2007). ProDiscover. Retrieved January 2, 2006, from VMWare. (2007). VMWare. Retrieved February 14, 2006, from VMWare. (2007). VMWare Server. Retrieved February 15, 2006, from Yasinsac, A., Erbacher, R. F., Marks, D. G., Pollitt, M. M., & Sommer, P. M. (2003). Computer Forensics Education. IEEE Security and Privacy, 1(4), pp
IN this paper we examine the application of the virtual
SMALL SCALE DIGITAL DEVICE FORENSICS JOURNAL, VOL. 1, NO. 1, JUNE 2007 1 Analysis of USB Flash Drives in a Virtual Environment Derek Bem and Ewa Huebner Abstract This paper is a continuation of our previous
Forensic Acquisition and Analysis of VMware Virtual Hard Disks
Forensic Acquisition and Analysis of VMware Virtual Hard Disks Manish Hirwani, Yin Pan, Bill Stackpole and Daryl Johnson Networking, Security and Systems Administration Rochester Institute of Technology
Digital Forensics Tutorials Acquiring an Image with FTK Imager
Digital Forensics Tutorials Acquiring an Image with FTK Imager Explanation Section Digital Forensics Definition The use of scientifically derived and proven methods toward the preservation, collection,
Comparing and Contrasting Windows and Linux Forensics. Zlatko Jovanovic. International Academy of Design and Technology
Comparing and Contrasting Windows and Linux Forensics Zlatko Jovanovic International Academy of Design and Technology Abstract Windows and Linux are the most common operating systems used on personal computers.
What is Digital Forensics?
DEVELOPING AN UNDERGRADUATE COURSE IN DIGITAL FORENSICS Warren Harrison PSU Center for Information Assurance Portland State University Portland, Oregon 97207 [email protected] What is Digital Forensics?
Live View. A New View On Forensic Imaging. Matthiew Morin Champlain College
Live View A New View On Forensic Imaging Matthiew Morin Champlain College Morin 1 Executive Summary The main purpose of this paper is to provide an analysis of the forensic imaging tool known as Live View.
VMWare Workstation 11 Installation MICROSOFT WINDOWS SERVER 2008 R2 STANDARD ENTERPRISE ED.
VMWare Workstation 11 Installation MICROSOFT WINDOWS SERVER 2008 R2 STANDARD ENTERPRISE ED. Starting Vmware Workstation Go to the start menu and start the VMware Workstation program. *If you are using
Digital Forensics. Tom Pigg Executive Director Tennessee CSEC
Digital Forensics Tom Pigg Executive Director Tennessee CSEC Definitions Digital forensics Involves obtaining and analyzing digital information as evidence in civil, criminal, or administrative cases Analyze
2! Bit-stream copy. Acquisition and Tools. Planning Your Investigation. Understanding Bit-Stream Copies. Bit-stream Copies (contd.
Acquisition and Tools COMP 2555: Principles of Computer Forensics Autumn 2014 http://www.cs.du.edu/2555 1 Planning Your Investigation! A basic investigation plan should include the following activities:!
2.6.1 Creating an Acronis account... 11 2.6.2 Subscription to Acronis Cloud... 11. 3 Creating bootable rescue media... 12
USER'S GUIDE Table of contents 1 Introduction...3 1.1 What is Acronis True Image 2015?... 3 1.2 New in this version... 3 1.3 System requirements... 4 1.4 Install, update or remove Acronis True Image 2015...
Journal of Digital Forensic Practice
Journal of Digital Forensic Practice Journal of Digital Forensic Practice, 2:57 61, 2008 Copyright Taylor & Francis Group, LLC ISSN: 1556-7281 print / 1556-7346 online DOI: 10.1080/15567280801958464 UDFP
MSc Computer Security and Forensics. Examinations for 2009-2010 / Semester 1
MSc Computer Security and Forensics Cohort: MCSF/09B/PT Examinations for 2009-2010 / Semester 1 MODULE: COMPUTER FORENSICS & CYBERCRIME MODULE CODE: SECU5101 Duration: 2 Hours Instructions to Candidates:
EC-Council Ethical Hacking and Countermeasures
EC-Council Ethical Hacking and Countermeasures Description This class will immerse the students into an interactive environment where they will be shown how to scan, test, hack and secure their own systems.
CSN08101 Digital Forensics. Module Leader: Dr Gordon Russell Lecturers: Robert Ludwiniak
CSN08101 Digital Forensics Lecture 1A: Introduction to Forensics Module Leader: Dr Gordon Russell Lecturers: Robert Ludwiniak Digital Forensics You will learn in this module: The principals of computer
System Recovery in Next to No Time by Jürgen Heyer
Product Test : Storagecraft ShadowProtect Server Edition 3.3 System Recovery in Next to No Time by Jürgen Heyer The advantages of an image-based backup system become obvious when a server fails to start
Unified Communications Installation & Configuration Guide
Unified Communications Installation & Configuration Guide Table of contents Page Applications License 1 Mitel 5110 Softphone 5 Click to Dial Application 22 Applications License Obtaining and Configuration
Digital Forensic. A newsletter for IT Professionals. I. Background of Digital Forensic. Definition of Digital Forensic
I Digital Forensic A newsletter for IT Professionals Education Sector Updates Issue 10 I. Background of Digital Forensic Definition of Digital Forensic Digital forensic involves the collection and analysis
Imaging Computing Server User Guide
Imaging Computing Server User Guide PerkinElmer, Viscount Centre II, University of Warwick Science Park, Millburn Hill Road, Coventry, CV4 7HS T +44 (0) 24 7669 2229 F +44 (0) 24 7669 0091 E [email protected]
Backup & Recovery. 10 Suite PARAGON. Data Sheet. Automatization Features
PARAGON Backup & Recovery 10 Suite Data Sheet Automatization Features Paragon combines our latest patented technologies with 15 years of expertise to deliver a cutting edge solution to protect home Windows
CONCEPT MAPPING FOR DIGITAL FORENSIC INVESTIGATIONS
Chapter 22 CONCEPT MAPPING FOR DIGITAL FORENSIC INVESTIGATIONS April Tanner and David Dampier Abstract Research in digital forensics has yet to focus on modeling case domain information involved in investigations.
How to remotely access your Virtual Desktop from outside the college using VMware View Client. How to guide
How to remotely access your Virtual Desktop from outside the college using VMware View Client How to guide Author: ICT Services Version: 1.0 Date: November 2015 Contents What is the VMware View Client?...
SOFTWARE INSTALLATION INSTRUCTIONS
AUDITGARD LGA Electronic Combination Lock SOFTWARE INSTALLATION INSTRUCTIONS Implementation Package The AuditGard Software implementation package includes: 707013 AuditGard Software Install CD 42145 Programming/Audit
NIST CFTT: Testing Disk Imaging Tools
NIST CFTT: Testing Disk Imaging Tools James R. Lyle, Ph.D. Computer Scientist National Institute of Standards and Technology 1. Introduction There is a critical need in the law enforcement community to
The Proper Acquisition, Preservation, & Analysis of Computer Evidence: Guidelines & Best-Practices
The Proper Acquisition, Preservation, & Analysis of Computer Evidence: Guidelines & Best-Practices Introduction As organizations rely more heavily on technology-based methods of communication, many corporations
Alternate Data Streams in Forensic Investigations of File Systems Backups
Alternate Data Streams in Forensic Investigations of File Systems Backups Derek Bem and Ewa Z. Huebner School of Computing and Mathematics University of Western Sydney [email protected] and [email protected]
Acronis Backup & Recovery 11
Acronis Backup & Recovery 11 Quick Start Guide Applies to the following editions: Advanced Server Virtual Edition Advanced Server SBS Edition Advanced Workstation Server for Linux Server for Windows Workstation
A+ Guide to Software: Managing, Maintaining, and Troubleshooting, 5e. Chapter 3 Installing Windows
: Managing, Maintaining, and Troubleshooting, 5e Chapter 3 Installing Windows Objectives How to plan a Windows installation How to install Windows Vista How to install Windows XP How to install Windows
Guidelines on Digital Forensic Procedures for OLAF Staff
Ref. Ares(2013)3769761-19/12/2013 Guidelines on Digital Forensic Procedures for OLAF Staff 1 January 2014 Introduction The OLAF Guidelines on Digital Forensic Procedures are internal rules which are to
CYBER FORENSICS (W/LAB) Course Syllabus
6111 E. Skelly Drive P. O. Box 477200 Tulsa, OK 74147-7200 CYBER FORENSICS (W/LAB) Course Syllabus Course Number: CSFS-0020 OHLAP Credit: Yes OCAS Code: 8134 Course Length: 130 Hours Career Cluster: Information
CribMaster Database and Client Requirements
FREQUENTLY ASKED QUESTIONS CribMaster Database and Client Requirements GENERAL 1. WHAT TYPE OF APPLICATION IS CRIBMASTER? ARE THERE ANY SPECIAL APPLICATION SERVER OR USER INTERFACE REQUIREMENTS? CribMaster
Webrecs IT infrastructure. The Webrecs IT backend explained and how we store, backup, protect and deliver your documents to you
Webrecs IT infrastructure The Webrecs IT backend explained and how we store, backup, protect and deliver your documents to you Sunday, April 21, 2013 Contents Introduction... 3 Data storage... 3 Data Centres...
Forensics on the Windows Platform, Part Two
1 of 5 9/27/2006 3:52 PM Forensics on the Windows Platform, Part Two Jamie Morris 2003-02-11 Introduction This is the second of a two-part series of articles discussing the use of computer forensics in
Synergy Controller Cloud Storage Features and Benefits
Synergy Controller Cloud Storage Features and Benefits The exploding popularity of cloud based data storage and application services is a direct result of the benefits they provide in virtually all business
Hands-On How-To Computer Forensics Training
j8fm6pmlnqq3ghdgoucsm/ach5zvkzett7guroaqtgzbz8+t+8d2w538ke3c7t 02jjdklhaMFCQHihQAECwMCAQIZAQAKCRDafWsAOnHzRmAeAJ9yABw8v2fGxaq skeu29sdxrpb25zidxpbmznogtheories...ofhilz9e1xthvqxbb0gknrc1ng OKLbRXF/j5jJQPxXaNUu/It1TQHSiyEumrHNsnn65aUMPnrbVOVJ8hV8NQvsUE
COMBOGARDPRO. 39E Electronic Combination Lock SOFTWARE INSTALLATION INSTRUCTIONS
COMBOGARDPRO 39E Electronic Combination Lock SOFTWARE INSTALLATION INSTRUCTIONS IMPLEMENTATION PACKAGE The ComboGard Pro Software implementation package includes: 707012 ComboGard Pro Software Install
Synergy Controller Cloud Storage Features and Benefits
Synergy Controller Cloud Storage Features and Benefits The exploding popularity of cloud based data storage and application services is a direct result of the benefits they seem to provide in virtually
HP MediaSmart Server Software Upgrade from v.2 to v.3
HP MediaSmart Server Software Upgrade from v.2 to v.3 Table of Contents Table of Contents Upgrade Your Server Software to HP MediaSmart Server v.3 2 Before You Begin 3 What's New 3 Features That Will
Chapter 4. Operating Systems and File Management
Chapter 4 Operating Systems and File Management Chapter Contents Section A: Operating System Basics Section B: Today s Operating Systems Section C: File Basics Section D: File Management Section E: Backup
Computer Forensics Processing Checklist. Pueblo High-Tech Crimes Unit
Computer Forensics Processing Checklist Pueblo High-Tech Crimes Unit Cmdr. Dave Pettinari Pueblo County Sheriff's Office [email protected] The purpose of this document is to provide computer forensic technicians
Understanding Backup and Recovery Methods
Lesson 8 Understanding Backup and Recovery Methods Learning Objectives Students will learn to: Understand Local, Online, and Automated Backup Methods Understand Backup Options Understand System Restore
Computer Forensics. Securing and Analysing Digital Information
Computer Forensics Securing and Analysing Digital Information Aims What is a computer? Where is the evidence? Why is digital forensics important? Seizing evidence Encryption Hidden files and folders Live
Chapter 12: Windows XP, Vista, and 7
Chapter 12: Windows XP, Vista, and 7 Complete CompTIA A+ Guide to PCs, 6e To distinguish between the Windows XP, Vista, and 7 operating systems To install, configure, and troubleshoot Windows XP, Vista,
Digital Forensics Lecture 3. Hard Disk Drive (HDD) Media Forensics
Digital Forensics Lecture 3 Hard Disk Drive (HDD) Media Forensics Current, Relevant Topics defendants should not use disk-cleaning utilities to wipe portions of their hard drives before turning them over
The following items are trademarks or registered trademarks of Kaba Mas in the United States and/or other countries. GITCON
The Gitcon Access Management Software Installation Guide is a publication of Kaba Mas LLC (hereinafter Kaba Mas). No part of this book may be reproduced or transmitted in any form or by any means, electronic
Information Technology Audit & Forensic Techniques. CMA Amit Kumar
Information Technology Audit & Forensic Techniques CMA Amit Kumar 1 Amit Kumar & Co. (Cost Accountants) A perfect blend of Tax, Audit & Advisory services Information Technology Audit & Forensic Techniques
C HFI C HFI. EC-Council. EC-Council. Computer Hacking Forensic Investigator. Computer. Computer. Hacking Forensic INVESTIGATOR
Page: 1 TM C HFI Computer C HFI Computer Hacking Forensic INVESTIGATOR Hacking Forensic INVESTIGATOR TM v8 v8 Page: 2 Be the leader. Deserve a place in the CHFI certified elite class. Earn cutting edge
Kaseya 2. User Guide. Version 7.0. English
Kaseya 2 Backup User Guide Version 7.0 English September 3, 2014 Agreement The purchase and use of all Software and Services is subject to the Agreement as defined in Kaseya s Click-Accept EULATOS as updated
HP MediaSmart Server Software Upgrade from v.1 to v.3
HP MediaSmart Server Software Upgrade from v.1 to v.3 Table of Contents Upgrade Your Server Software to HP MediaSmart Server v.3 2 Before You Begin 3 What's New... 3 Features That Will Change... 4 Prepare
Bare Metal Recovery Quick Start Guide
Bare Metal Recovery Quick Start Guide Revisions Document Control Version 5.4.3 Status Changes Date Final Created. August 2014 Copyright 2003-2014 Intronis, Inc. All rights reserved. 1 Table of Contents
Practice Exercise March 7, 2016
DIGITAL FORENSICS Practice Exercise March 7, 2016 Prepared by Leidos CyberPatriot Forensics Challenge 1 Forensics Instruction Guide Introduction The goal of this event is to learn to identify key factors
EnCase Portable. Extend Your Forensic Reach with Powerful Triage & Data Collection
GUIDANCE SOFTWARE EnCase Portable EnCase Portable Extend Your Forensic Reach with Powerful Triage & Data Collection GUIDANCE SOFTWARE EnCase Portable EnCase Portable Triage and Collect with EnCase Portable
Quick Start Guide for VMware and Windows 7
PROPALMS VDI Version 2.1 Quick Start Guide for VMware and Windows 7 Rev. 1.1 Published: JULY-2011 1999-2011 Propalms Ltd. All rights reserved. The information contained in this document represents the
Implementing and Managing Windows Server 2008 Hyper-V
Course 6422A: Implementing and Managing Windows Server 2008 Hyper-V Length: 3 Days Language(s): English Audience(s): IT Professionals Level: 300 Technology: Windows Server 2008 Type: Course Delivery Method:
6 USING WINDOWS XP 6.1 INTRODUCTION
6 USING WINDOWS XP 6.1 INTRODUCTION The windows operating system started with the introduction of Windows OS and Windows for work group for networking. Since then it has come a long way and Windows 95,
Course Syllabus. Microsoft Dynamics GP Installation & Configuration. Key Data. Introduction. Audience. At Course Completion
Course Syllabus Microsoft Dynamics GP Installation & Configuration Key Data Course Number: 8814B Number of Days: 3 Available: August, 2007 Languages: U.S. English Format: Instructor-Led Training (lecture
Getting Physical with the Digital Investigation Process
Getting Physical with the Digital Investigation Process Brian Carrier Eugene H. Spafford Center for Education and Research in Information Assurance and Security CERIAS Purdue University Abstract In this
HP RDX Continuous Data Protection Software Quickstart Guide
HP RDX Continuous Data Protection Software Quickstart Guide *5697-3351* HP Part Number: 5697-3351 Published: May 2014 Edition: Fourth Copyright 2008 2014 Hewlett-Packard Development Company, L.P. Microsoft,
DriveLock and Windows 7
Why alone is not enough CenterTools Software GmbH 2011 Copyright Information in this document, including URL and other Internet Web site references, is subject to change without notice. Unless otherwise
ScoMIS Encryption Service
Introduction This guide explains how to install the ScoMIS Encryption Service Software onto a laptop computer. There are three stages to the installation which should be completed in order. The installation
VMWARE Introduction ESX Server Architecture and the design of Virtual Machines
Introduction........................................................................................ 2 ESX Server Architecture and the design of Virtual Machines........................................
Where is computer forensics used?
What is computer forensics? The preservation, recovery, analysis and reporting of digital artifacts including information stored on computers, storage media (such as a hard disk or CD-ROM), an electronic
Lecture outline. Computer Forensics and Digital Investigation. Defining the word forensic. Defining Computer forensics. The Digital Investigation
Computer Forensics and Digital Investigation Computer Security EDA263, lecture 14 Ulf Larson Lecture outline! Introduction to Computer Forensics! Digital investigation! Conducting a Digital Crime Scene
CentreWare Internet Services Setup and User Guide. Version 2.0
CentreWare Internet Services Setup and User Guide Version 2.0 Xerox Corporation Copyright 1999 by Xerox Corporation. All rights reserved. XEROX, The Document Company, the digital X logo, CentreWare, and
ArCycle vmbackup. for VMware/Hyper-V. User Guide
ArCycle vmbackup for VMware/Hyper-V User Guide 2 Copyright Copyright ArCycle Software, Ltd., 2011-2014. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system,
Centran Version 4 Getting Started Guide KABA MAS. Table Of Contents
Page 1 Centran Version 4 Getting Started Guide KABA MAS Kaba Mas Welcome Kaba Mas, part of the world-wide Kaba group, is the world's leading manufacturer and supplier of high security, electronic safe
Updates Click to check for a newer version of the CD Press next and confirm the disc burner selection before pressing finish.
Backup. If your computer refuses to boot or load Windows or if you are trying to restore an image to a partition the Reflect cannot lock (See here), and then you will have to start your PC using a rescue
Information in this document, including URL and other Internet Web site references, is subject to change without notice. Unless otherwise noted, the
Information in this document, including URL and other Internet Web site references, is subject to change without notice. Unless otherwise noted, the example companies, organizations, products, domain names,
Total Backup Recovery 7
7 TM 7 Simplify and automate backup and recovery manageability while maintaining business continuity 7 Advanced Server is FarStone s next generation backup and recovery utility to protect your business
Total Backup Recovery 7
7 TM 7 Automat backup and restore management for all networked laptops & workstations from a centralized administrating console 7 Advanced Workstation assures that critical business information is well
Acronis True Image 2015 REVIEWERS GUIDE
Acronis True Image 2015 REVIEWERS GUIDE Table of Contents INTRODUCTION... 3 What is Acronis True Image 2015?... 3 System Requirements... 4 INSTALLATION... 5 Downloading and Installing Acronis True Image
Overview of Computer Forensics
Overview of Computer Forensics Don Mason, Associate Director National Center for Justice and the Rule of Law University of Mississippi School of Law [These materials are based on 4.3.1-4.3.3 in the National
The Tor VM Project. Installing the Build Environment & Building Tor VM. Copyright 2008 - The Tor Project, Inc. Authors: Martin Peck and Kyle Williams
The Tor VM Project Installing the Build Environment & Building Tor VM Authors: Martin Peck and Kyle Williams Table of Contents 1. Introduction and disclaimer 2. Creating the virtualization build environment
Protecting Virtual Servers with Acronis True Image
Protecting Virtual Servers with Acronis True Image Protecting Virtual Servers with Acronis True Image In This Paper Protecting Virtual Servers with Acronis True Image...3 Virtual Machines: The Data Protection
Analyzer 2.0. Installation Guide. Contents
Analyzer 2.0 Analyzer 2.0 is a comprehensive suite of tools designed to help you analyze complex aqueous and multisolvent electrolyte solution chemistry, thermophysical properties, phase behavior and corrosion
Hyper-V Server 2008 Getting Started Guide
Hyper-V Server 2008 Getting Started Guide Microsoft Corporation Published: October 2008 Author: Cynthia Nottingham Abstract This guide helps you become familiar with Microsoft Hyper-V Server 2008 by providing
Using Virtual PC 7.0 for Mac with GalleryPro
Using Virtual PC 7.0 for Mac with GalleryPro Installing and Configuring What is Virtual PC for Mac? Virtual PC (VPC) is emulation software that simulates an actual (though virtual) Windows computer running
Remote Desktop Services
Remote Desktop Services White Paper November 2014 Maximizing the Value and Performance of QuickBooks Enterprise with Remote Desktop Services Formerly known as Windows Terminal Services, Remote Desktop
Imaging License Server User Guide
IMAGING LICENSE SERVER USER GUIDE Imaging License Server User Guide PerkinElmer Viscount Centre II, University of Warwick Science Park, Millburn Hill Road, Coventry, CV4 7HS T +44 (0) 24 7669 2229 F +44
RecoverIt Frequently Asked Questions
RecoverIt Frequently Asked Questions Windows Recovery FAQs When can I use Windows Recovery application? This application is used to recover the deleted files from internal or external storage devices with
BULLGUARD BAckUp GUIDE
BULLGUARD backup GUIDE CONTENTS BullGuard Backup introduction page 3 Installing BullGuard Backup page 6 Uninstalling BullGuard Backup page 11 Registering BullGuard Backup: creating an account page 12 Running
Installing Windows On A Macintosh Or Linux Using A Virtual Machine
Installing Windows On A Macintosh Or Linux Using A Virtual Machine At Shaw Programs, the software we develop is made using Microsoft Access. As with all Microsoft Software it requires Windows in order
EasyLock. User Manual. Intuitive Encryption Application for portable Storage Devices
1 EasyLock User Manual Intuitive Encryption Application for portable Storage Devices User Manual Version 1.0.0.8 2004-2010 CoSoSys Ltd. 2 Table of Contents Table of Contents... 2 1. Introduction... 3 2.
CODESOFT Installation Scenarios
CODESOFT Installation Scenarios NOTES: CODESOFT is a separate install from existing versions of CODESOFT. You will need to make note of your current settings (default directories, etc.) so you can duplicate
Computer Forensic Tools. Stefan Hager
Computer Forensic Tools Stefan Hager Overview Important policies for computer forensic tools Typical Workflow for analyzing evidence Categories of Tools Demo SS 2007 Advanced Computer Networks 2 Important
1. System Requirements
BounceBack Data Transfer 14.2 User Guide This guide presents you with information on how to use BounceBack Data Transfer 14.2. Contents 1. System Requirements 2. Attaching Your New Hard Drive To The Data
Developing Computer Forensics Solutions for Terabyte Investigations
Developing Computer Forensics Solutions for Terabyte Investigations Eric Thompson Corporation Orem, Utah USA www.accessdata.com Overview Computer Forensic Definition, Objectives and Policies History of
STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER
Notes: STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER 1. These instructions focus on installation on Windows Terminal Server (WTS), but are applicable
After going through this lesson you would be able to:
18 :: Data Entry Operations 2 Operating System 2.1 INTRODUCTION The operating system in these days uses a graphical user interface (GUI). Here you do not have to remember all the commands by heart. The
White paper: Unlocking the potential of load testing to maximise ROI and reduce risk.
White paper: Unlocking the potential of load testing to maximise ROI and reduce risk. Executive Summary Load testing can be used in a range of business scenarios to deliver numerous benefits. At its core,
Report on virtualisation technology as used at the EPO for Online Filing software testing
Report on virtualisation technology as used at the EPO for Online Filing software testing Virtualisation technology lets one computer do the job of multiple computers, all sharing the resources - including
VMware/Hyper-V Backup Plug-in User Guide
VMware/Hyper-V Backup Plug-in User Guide COPYRIGHT No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, photocopying,
Parallels Desktop for Mac
Parallels Software International, Inc. Parallels Desktop for Mac Quick Start Guide 3.0 (c) 2005-2007 Copyright 2006-2007 by Parallels Software International, Inc. All rights reserved. Parallels and Parallels
Meridian 1 Meridian 1 Attendant PC LAN Interface Installation Guide
Meridian 1 Meridian 1 Attendant PC LAN Interface Installation Guide Document Number: P0874391 Document Release: Standard 1.00 Date: November 1997 Year Publish FCC TM 1997 All rights reserved Printed in
S&G Audit Lock. Audit Trail Software Manual
S&G Audit Lock Audit Trail Software Manual The Sargent & Greenleaf Audit Lock is designed to provide a high level of security. One of the ways they accomplish this is by offering detailed audit trails.
16.4.3 Lab: Data Backup and Recovery in Windows XP
16.4.3 Lab: Data Backup and Recovery in Windows XP Introduction Print and complete this lab. In this lab, you will back up data. You will also perform a recovery of the data. Recommended Equipment The
GUARD1 PLUS SE Administrator's Manual
GUARD1 PLUS SE Administrator's Manual Version 4.4 30700 Bainbridge Road Solon, Ohio 44139 Phone 216-595-0890 Fax 216-595-0991 [email protected] www.guard1.com i 2010 TimeKeeping Systems, Inc. GUARD1 PLUS
DriveLock and Windows 8
Why alone is not enough CenterTools Software GmbH 2013 Copyright Information in this document, including URL and other Internet Web site references, is subject to change without notice. Unless otherwise
