Volume Shadow Copy and Registry Forensics

Mega Carder

Guru
BFD MEMBER
LEGEND
ULTIMATE
SELLER
SUPREME
MEMBER
BFD Legacy
Joined
Mar 14, 2025
Messages
1,348
Reaction score
15,569
Deposit
6,350$
What is covered in this PDF?
  • Volume Shadow Copy Basics
  • Shadow Copies on a Live Machine
  • Some Command Line
  • Shadow Explorer
  • Working with Disk Images
  • Some Registry Keys

Overwritten data: Values and data in keys such as typed URLs may be over-written from one session to another

Registry Related Timeline Analysis: You may be able to determine user activity during a more extended time frame

Anti-Anti-Forensics: Technologically sophisticated users may attempt to “clean” their Registry
 
Top Bottom