Shadow Forensics
Shadow Copy (also called Volume Snapshot Service or VSS, or Previous Versions in Windows Vista) is a feature introduced with Windows XP with SP1, Windows Server 2003, and available in all releases of Microsoft Windows thereafter, that allows taking manual or automatic backup copies or snapshots of a file or folder on a specific volume [...]
Read Full Post | Make a Comment ( None so far )SANS has Forensics Site Avaiable
In an effort to increase the opportunities for information exchange SANS has opened their Forensics site which can be found at:
http://forensics.sans.org
Chain of Custody – Development of Procedures
1. Developing of Procedures
As with any area that can impact your business, organization or institution procedures need to be developed that will assist in focusing effort and work. The chain of custody is no exception to this rule. In fact, the entire chain of custody is null with out a written procedure. Your policies will [...]


