PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 29, 2024Deleted Journal2 citationsOpen Access

Digital Forensics and Windows Sandbox as Anti-forensics tool

View Full Paper
MUMohammed Yousuf UddinMAMohammad Mazhar AfzalSASultan Ahmad

Key Points

Key points are not available for this paper at this time.

Abstract

Digital forensics is facing new challenges with rise in new anti-forensics techniques and tools including virtualization. Virtualization can be used as shield against different types of attacks, at the same time it can be leveraged by attackers as anti-forensics tool. Forensic investigators face enormous challenges while collecting the digital evidences in case where virtualization is used by an attacker. Virtualization comes in different forms, one of the difficulty form is light weight virtualization. Microsoft windows operating system offers sandbox light weight virtualization. Microsoft windows sandbox is an isolated testing environment to run programs or open files without affecting the application, system, or platform on which they run. After closing the sandbox nothing persists on the device, everything is discarded. This paper reveals the anti-forensics capabilities of sandbox and possible solutions to collect the forensics artefacts using windows registry. Registry analysis revealed that only use of sandbox on host operating system is discoverable and activities and data inside the sandbox are discarded permanently.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Uddin et al. (2024) studied this question.

synapsesocial.com/papers/68e77088b6db6435876e58e5https://doi.org/10.47392/irjaeh.2024.0049
Ask AI
Helpful
Bookmark
Share
View Full Paper