A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2020; you can also visit the original URL.
The file type is application/pdf
.
SlackStick: Signature-Based File Identification for Live Digital Forensics Examinations
2015
2015 European Intelligence and Security Informatics Conference
A digital forensics investigation may involve procedures for both live forensics and for gathering evidence from a device in a forensics laboratory. Due to the focus on capturing volatile data during a live forensics investigation, tools have been developed that are aimed at capturing specific data surrounding state information. However, there may be circumstances whereby non-volatile data analysis, such as the identification of files of interest, is also required. In such an investigation, the
doi:10.1109/eisic.2015.28
dblp:conf/eisic/HegartyH15
fatcat:fm2hc4xyrrcqld22jl4mrxr2ae