ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!
Home
Upgrade
Credits
Help
Search
Awards
Achievements
 1477

Digital Forensics

by Testhuman - 04-23-2018 - 05:42 AM
#1
How to collect evidence from a Live system which is locked and password unknown?
Reply
#2
Forensic evidence is stored on the device.
I recommend getting a writeblocker and then going through the contents of the drive.
If you can't dismount the drive, you should just recover the password via an admin/global admin.

If you lost any and all access, it's unlikely you'll get back in the system without turning off the system.
Really depends if it's windows, linux or a different OS.
Reply

Users browsing: 2 Guest(s)