'guideline'에 해당되는 글 1건
- 2012.06.12 RFC3227
영문
국문번역본
2.1 Order of Volatility
When collecting evidence you should proceed from the volatile to the
less volatile. Here is an example order of volatility for a typical
system.
- registers, cache
- routing table, arp cache, process table, kernel statistics,
memory
- temporary file systems
- disk
- remote logging and monitoring data that is relevant to the
system in question
- physical configuration, network topology
- archival media
'Article > Forensics' 카테고리의 다른 글
Windows Forensics (0) | 2013.07.08 |
---|---|
경찰수사연수원 디지털포렌식 챌린지 (0) | 2010.11.01 |
형사소송학회 디지털포렌식 전문가 2급 자격시험 (0) | 2010.09.28 |
Guidance Software, Tableau 인수 (0) | 2010.05.11 |
SANS Forensics Whitepapers (2) | 2010.02.26 |