DIGITAL FORENSIC TOOKS:
1. USB FORENSIC
What value could this artifact have for investigation?
What kinds of information can you extract?
2. WINDOWS REGISTRY
What value could this artifact have for investigation?
What kinds of information can you extract?
What were they following originally designed for
What kind of forensic value could they provide in the in adigital investigation?
What are some of the limitations of each type of theartifact?
Link Files
Prefetch
ShimCache
Shellbags
Jump lists
VSS
Event Logs