How to collect evidence from a Live system which is locked and password unknown?
Forensic evidence is stored on the device.
I recommend getting a writeblocker and then going through the contents of the drive.
If you can't dismount the drive, you should just recover the password via an admin/global admin.
If you lost any and all access, it's unlikely you'll get back in the system without turning off the system.
Really depends if it's windows, linux or a different OS.
I recommend getting a writeblocker and then going through the contents of the drive.
If you can't dismount the drive, you should just recover the password via an admin/global admin.
If you lost any and all access, it's unlikely you'll get back in the system without turning off the system.
Really depends if it's windows, linux or a different OS.
Users browsing: 3 Guest(s)