Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.


Share this Page URL
Help

What Can Be Gained by Booting the Captur... > Using the System to Demonstrate the ... - Pg. 242

242 Chapter9·ForensicAnalysis Virtualization May Permit You to Observe Behavior That Is Only Visible While Live When Windows starts, there are a myriad of places that can contain instructions to be executed upon startup. Looking in each location that can contain startup instructions and trying to interpret what those text and binary instructions might do is next to impossible. However, if you could boot the system in a virtual instance, you might be able to tell easily that the malicious code you were investigating had replaced the background with a fake security alert. In addition, you run the system and collect network information from the network about open ports and network connections that are initiated or accepted. You can add tools that can look for and interpret information on VM running the suspect's image. Using the System to Demonstrate the Meaning of the Evidence