A TOOL FOR EXTRACTING STATIC AND VOLATILE FORENSIC ARTIFACTS OF WINDOWS 8.x APPS - Advances in Digital Forensics XI
Conference Papers Year : 2015

A TOOL FOR EXTRACTING STATIC AND VOLATILE FORENSIC ARTIFACTS OF WINDOWS 8.x APPS

Abstract

Microsoft Windows 8 introduced lightweight sandboxed applications called “apps” that provide a full range of functionality on top of touchenabled displays. Apps offer a wide range of functionality, including media editing, file sharing, Internet surfing, cloud service usage, online social media activities and audio/video streaming for the Windows 8 and 8.1 operating systems. The use of these apps produces much more forensically-relevant information compared with conventional application programs. This chapter describes MetroExtractor, a tool that gathers static and volatile forensic artifacts produced by Windows apps. The volatile artifacts are extracted from the hibernation and swap files available on storage media. MetroExtractor creates a timeline of user activities and the associated data based on the collected artifacts. The tool appears to be the first implementation for extracting forensicallysound static and volatile Windows 8 app artifacts from a system hard disk.
Fichier principal
Vignette du fichier
978-3-319-24123-4_18_Chapter.pdf (271.94 Ko) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-01449065 , version 1 (30-01-2017)

Licence

Identifiers

Cite

Shariq Murtuza, Robin Verma, Jayaprakash Govindaraj, Gaurav Gupta. A TOOL FOR EXTRACTING STATIC AND VOLATILE FORENSIC ARTIFACTS OF WINDOWS 8.x APPS. 11th IFIP International Conference on Digital Forensics (DF), Jan 2015, Orlando, FL, United States. pp.305-320, ⟨10.1007/978-3-319-24123-4_18⟩. ⟨hal-01449065⟩
194 View
967 Download

Altmetric

Share

More