Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Windows Live Forensics (Part 1 of 2)

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
4,456
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jan 28, 2010

This video illustrates some common forensic tools that can be used to acquire evidence from a running Windows system.

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (4)

Sign In or Sign Up now to post a comment!
  • @PADDYzIRISHzMAN open cmd and type tasklist its the same thing

  • The only flaw that i can see is that you have to install a file to make the 'pslist' and other commands associated with it. when it comes to digital forensics and crime scenes, you cant install anything on the computer being investigated.

  • Good video though, it's obvious you know your stuff.

  • While command line looks cool, using the program Process Explorer from sysinternals will show you all the running processes, dll files in use, strings, handles, tcp/ip connections, ACLs and files actual location, how much cpu a particular process is using, breakdowns of resources in use by a process, and if it's a generic service container (such as svchost) it will show what services it is hosting. You can also manipulate the process and easily identify what process a window belongs to.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more