Log File Identification, Preservation, Collection, and Acquisition

Graeme Edwards · 2019

Logs record events on the computers and the many devices that are part of a network. The activities they record may be valuable evidence to the investigators as they try to understand what has happened, the extent of the activity, and the identity of the person who may be involved. Sources of computer logs include operating systems, applications programs, and the many devices that make up a computer network. This chapter provides a general understanding of the sources and meaning of the variety of logs an investigator may encounter. It focuses on those originating from Windows operating systems to provide an understanding of what evidence is available from logs and where. Although an experienced digital examiner will generally undertake this line of inquiry, it is valuable information an investigator will benefit from knowing and having a general understanding of.

Read the paper · More papers on PaperTik