±Your Account
Membership:
New Today: 0
New Yesterday: 4
Overall: 24209
Visitors: 34±Latest Webinar
±Latest Articles
· Android Forensics
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
· Geo-tagging & Photo Tracking On iOS
· KS – an open source bash script for indexing data
· Mobile Device Geotags & Armed Forces
· Categorization of embedded system forensic collection methodologies
· Interpretation of NTFS Timestamps
· What are ‘gdocs’? Google Drive Data – part 2
· What are ‘gdocs’? Google Drive Data
· Bad Sector Recovery
· Forensic Artifact: Malware Analysis in Windows 8
±Follow Us
±Latest Jobs
Back to top
Skip to content
Skip to menu
Back to top
Back to main
Skip to menu
Go to page 1, 2, 3, 4 Next
Well, Microsoft has constructed the metro app to cache files much like an internet browser caches for quick access to data when it's opened up again. Such caching can be turned off in settings, but I don't know if app developers can do it with a specific app or not. Most of them won't as it degrades and slows the "speed" of their app loading.
This is great for us as it gives us a lot of residual cache data to examine and piece together in a given investigation. However, expect Microsoft to possibly secure this open cache in future service packs to mitigate any security issues that might hijack such cache data...
Windows 8 Forensics - A First Look
Windows 8 Forensics - A First Look
Posted: Wed Aug 29, 2012 8:48 am
Please use this topic for discussion of the webinar
Windows 8 Forensics - A First Look
presented by Josh Brunty, Assistant Professor of Digital Forensics at Marshall University.
If you encountered any problems viewing the webinar please try the YouTube version here. Additionally, a PDF with slides from the presentation can be found here.
Kind regards,
Jamie
_________________
Jamie Morris
Forensic Focus
Web: www.forensicfocus.com
Blog: www.forensicfocus.com/blog
Twitter: twitter.com/ForensicFocus
LinkedIn: www.linkedin.com/in/jamiemorris
Last edited by jamie on Wed Aug 29, 2012 10:21 am; edited 2 times in total
Windows 8 Forensics - A First Look
presented by Josh Brunty, Assistant Professor of Digital Forensics at Marshall University.
If you encountered any problems viewing the webinar please try the YouTube version here. Additionally, a PDF with slides from the presentation can be found here.
Kind regards,
Jamie
_________________
Jamie Morris
Forensic Focus
Web: www.forensicfocus.com
Blog: www.forensicfocus.com/blog
Twitter: twitter.com/ForensicFocus
LinkedIn: www.linkedin.com/in/jamiemorris
Last edited by jamie on Wed Aug 29, 2012 10:21 am; edited 2 times in total
-

jamie - Site Admin
Re: Windows 8 Forensics - A First Look
Posted: Wed Aug 29, 2012 9:13 am
Thank you Jamie!
-Art-
-Art-
- jamieSorry everyone, looks like Meetingburner can't hand the volume - please try the YouTube version at youtu.be/uhCooEz9FQs
-

4n6art - Senior Member
Re: Windows 8 Forensics - A First Look
Posted: Wed Aug 29, 2012 9:47 am
I got as far as the mention of "apps" having there own local storage space. Any indication that user data archived will by Windows or will this be up to each app?
Thanks,
_________________
Greg Marshall, EnCE
Thanks,
_________________
Greg Marshall, EnCE
-

gmarshall139 - Senior Member
Re: Windows 8 Forensics - A First Look
Posted: Wed Aug 29, 2012 9:48 am
Hey folks. it's Josh Brunty and I'll be monitoring this message board thread throughout the day for any questions you might have regarding Windows 8...
To those interested, I'd suggest downloading and playing with the newest Windows 8 Release Preview, which you can obtain from Microsoft from the following link:
windows.microsoft.com/...8/download
Also, here is a TechNet overview of the features to be included in Windows 8 (Microsoft is changing the names of some features again) so this a good repository of those features that are available:
technet.microsoft.com/...ows-8.aspx
Once again, thanks for the interest in the presentation (so much so we crashed the meeting room).
-Josh
To those interested, I'd suggest downloading and playing with the newest Windows 8 Release Preview, which you can obtain from Microsoft from the following link:
windows.microsoft.com/...8/download
Also, here is a TechNet overview of the features to be included in Windows 8 (Microsoft is changing the names of some features again) so this a good repository of those features that are available:
technet.microsoft.com/...ows-8.aspx
Once again, thanks for the interest in the presentation (so much so we crashed the meeting room).
-Josh
-

brunty11 - Member
Re: Windows 8 Forensics - A First Look
Posted: Wed Aug 29, 2012 10:15 am
- gmarshall139I got as far as the mention of "apps" having there own local storage space. Any indication that user data archived will by Windows or will this be up to each app?
Thanks,
Well, Microsoft has constructed the metro app to cache files much like an internet browser caches for quick access to data when it's opened up again. Such caching can be turned off in settings, but I don't know if app developers can do it with a specific app or not. Most of them won't as it degrades and slows the "speed" of their app loading.
This is great for us as it gives us a lot of residual cache data to examine and piece together in a given investigation. However, expect Microsoft to possibly secure this open cache in future service packs to mitigate any security issues that might hijack such cache data...
-

brunty11 - Member
Re: Windows 8 Forensics - A First Look
Posted: Wed Aug 29, 2012 10:33 am
Hi,
If it's not too late i'd like to know a bit more about Windows 8 shadow copy system (compared to windows 7 / Vista)
It seems that it is not in the presentation (after the registry)
Kind regards
Jean-Philippe Noat
If it's not too late i'd like to know a bit more about Windows 8 shadow copy system (compared to windows 7 / Vista)
It seems that it is not in the presentation (after the registry)
Kind regards
Jean-Philippe Noat
-

uriel98 - Newbie
Re: Windows 8 Forensics - A First Look
Posted: Wed Aug 29, 2012 10:34 am
Will PsTools work on this Windows 8, as how its been very useful all the while
-

soloman - Member
















