OS FORENSIC
OBJECTIVES
What is an OS?
Functions of an OS
OPERATING SYSTEM INTERFACE
What is OS Forensic?
Windows forensics
Collecting Volatile Information
System Time
LoggedOn Users
Open Files
Network Connections
Process Information
Process to Port Mapping
Network Status
Print Spool Files
Clipboard Contents
• • The clipboard is simply an area of memory where data can be
stored for later use.
• • Most Windows applications provide this functionality through the
Edit option on
• the menu bar.
• • Clicking Edit reveals a drop-down menu with choices like Cut, Copy,
and Paste
Collecting Non Volatile Information
Windows Registry Analysis
Event Logs
Slack Space
Virtual Memory
Page File
Windows Search Index
Collecting Hidden Partition Information
MAC FORENSICS