±Forensic Focus Partners

Become an advertising partner

±Your Account


Username
Password

Forgotten password/username?

Site Members:

New Today: 0 Overall: 34072
New Yesterday: 2 Visitors: 152

±Follow Forensic Focus

Forensic Focus Facebook PageForensic Focus on TwitterForensic Focus LinkedIn GroupForensic Focus YouTube Channel

RSS feeds: News Forums Articles

±Latest Articles

RSS Feed Widget

±Latest Webinars

Live Acquisition

Computer forensics training and education issues. If you are looking for topic suggestions for your project, thesis or dissertation please post here rather than the general discussion forum.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
 
  

Live Acquisition

Post Posted: Thu Mar 29, 2018 2:21 pm

Hi guys,

I am a bit confused how to start live acquisition on running machine (Laptop(Windows 10)) which is being password-protected. Let's assume i cannot ask anyone for the password to get access to a suspect account.

How does live acquision works?

I mean it cannot be that machine isn't protected with password so what kind of actions has to be done to conduct live acquisition?

Thank you!  

mhibert
Member
 
 
  

Re: Live Acquisition

Post Posted: Thu Mar 29, 2018 9:20 pm

Are you studying for a computer forensics degree or class?  

UnallocatedClusters
Senior Member
 
 
  

Re: Live Acquisition

Post Posted: Fri Mar 30, 2018 5:21 am

- mhibert
How does live acquision works?


No desktop - no live acquisition.
You need access to the machine to start several software with admin permissions.

Your question gives me the impression you are a newbie in Digital Forensics. Do you have access to a Technical Library or Amazon perhaps to read some books about the basics of DFIR?  

Bunnysniper
Senior Member
 
 
  

Re: Live Acquisition

Post Posted: Fri Mar 30, 2018 9:05 am

- Bunnysniper

No desktop - no live acquisition.


Since the OP specified in his question a laptop, the way you phrased that might be ambiguous...

... ducks ...

Wink

jaclaz
_________________
- In theory there is no difference between theory and practice, but in practice there is. - 

jaclaz
Senior Member
 
 
  

Re: Live Acquisition

Post Posted: Fri Mar 30, 2018 9:33 am

- mhibert
I mean it cannot be that machine isn't protected with password


Well, yes. That's one of the possible starting points. There are others. Sometimes you have to start to devise a method something like a year before you need it.

In some situations you can't do it.

"Live" doesn't mean that you're always successful. Failure is one of the possible ending points.

Its very often up to you or your team to understand the target system well enough to devise a possible solution. It is not a Carnegie. There's no easy book that works every time on how to win friends, influence people and do live acquistions.  

athulin
Senior Member
 
 

Page 1 of 1