![]() |
![]() |
![]() |
Vista Forensics, Part One
Saturday, April 28th, 2007
While the fundamental principles of computer forensics remain largely unchallenged, the landscape upon which investigators operate
is constantly changing. A combination of new technologies and changing habits of use means that forensic examiners must always strive to keep up to date with the latest developments. One of the most anticipated new product releases this year is the Microsoft operating system Windows Vista. Vista was under development for a long time with Microsoft promising a raft of new features together with major improvements to security.
Regardless of how quickly Vista is adopted by existing businesses and consumers - and there are good reasons to suppose that its uptake will be somewhat slower than Microsoft’s early estimates - it seems almost certain that this new OS will continue the trend of Microsoft’s dominance in the operating system market and wise computer forensics professionals will want to start thinking about the implications now. It should also be borne in mind that Vista will not only become a platform for investigation but also, at some stage, the operating system used by many investigators themselves for acquiring, analyzing and reporting.
At the time of writing, Vista is a very new product for almost all businesses and consumers and its features lie waiting to be fully discovered. In fact, the impact of Vista will not be determined solely through its technological offerings but also by the way in which it shapes users’ patterns of behaviour.
This article, the first in a two-part series, takes a high level look at what we know now about those changes in Vista which seem likely to have the most impact on computer forensic investigations, starting with the built-in encryption, backup, and system protection features. Next time, part two will continue the discussion with a concentration on typical user activities such as web browser and e-mail usage.
Before looking at the encryption and backup changes in Vista, let’s take a quick look at the various flavours of Vista which are available… Notes On Vista Forensics, Part One
Popular Posts
Please read our Disclaimer




