Ανάπτυξη πλαισίου αυτόματης ψηφιακής ανάλυσης (Windows Forensics Framework), ενός υπολογιστή με εγκατεστημένο το λειτουργικό σύστημα των Windows
Development of an automated Forensics Framework, for computers with Windows operating system
![Thumbnail](/xmlui/bitstream/handle/unipi/10552/Zoannos_Nikolaos.pdf.jpg?sequence=4&isAllowed=y)
Master Thesis
Author
Ζωάννος, Νικόλαος Μ.
Date
2017View/ Open
Keywords
Εγκληματολογική έρευνα Windows 7 ; Εγκληματολογική έρευνα Windows 8 ; Εγκληματολογική έρευνα Windows 10 ; Συλλογή και ανάλυση πληροφοριών μνήμης ; Συλλογή και ανάλυση πληροφοριών σκληρού δίσκου ; Συλλογή και ανάλυση πληροφοριών εξωτερικών μέσων αποθήκευσης ; Συλλογή και ανάλυση πληροφοριών μητρώου λειτουργικού ; Forensics ; Windows 7 forensics ; Windows 8 forensics ; Windows 10 forensics ; RAM forensics ; HDD forensics ; USB forensics ; Registry forensics ; TimelineAbstract
The subject of this master’s thesis is to examine a computer (activated or deactivated) in which has been installed the windows 7 or 8 or 10 and it has been traced, on it, a penetration, using the web. Throughout this examination the information which are been collected and analyzed, are able to constitute the evidence of a trial.
This master’s thesis begins by describing the value of windows forensics and continues with the description of the software that has been created in order to collect the necessary information from system’s hardware, registry, ram, web browsers, hard disk drives and usb flash disks.
Thereinafter follows the description of the software about the analysis of the information that has been collected. The purpose of this analysis is to give to the analysts farther more information regarding the chronology of events (timeline) and the exent of the damages. At the end of this analysis the software creates a table which contains important information that is able to constitute the evidence of a trial.