アンタイ・フォレンジック妖怪の独り言

基本的にはデジタル・フォレンジックの技術について取り扱っていますが、記載内容には高確率で誤りが含まれる可能性があります。

Windows 8 参考URL(順番に特に意味なし)

Windows 8 Forensics Part 1, Part 2, Part 3
http://www.youtube.com/watch?v=p8UHmoXtwsk
http://computerforensics.champlain.edu/blog/windows-8-forensics
http://computerforensics.champlain.edu/blog/windows-8-forensics-part-2
http://computerforensics.champlain.edu/blog/windows-8-forensics-part-3

Windows 8 Forensic Guide
http://propellerheadforensics.files.wordpress.com/2012/05/thomson_windows-8-forensic-guide2.pdf

Windows 8 Forensics - SANS Computer Forensics
https://computer-forensics.sans.org/summit-archives/2012/windows-8-recovery-forensics-understanding-the-three-rs.pdf

Windows 8 Forensic Overview
http://randomthoughtsofforensics.blogspot.jp/2011/12/windows-8-forensic-overview.html

Windows 8 Forensic - File History
http://randomthoughtsofforensics.blogspot.jp/2012/06/windows-8-forensic-file-history.html

□DFIR Webcast: Windows 8 Forensics: FileHistory Service
https://www.sans.org/webcasts/windows-8-forensics-filehistory-service-95325

□Forensic Artifact: Malware Analysis in Windows 8
http://resources.infosecinstitute.com/forensic-analysis-windows-8/

Windows 8 Forensics: Recycle Bin
http://www.infosecisland.com/blogview/22234-Windows-8-Forensics-Recycle-Bin.html

Windows 8: Important Considerations for Computer Forensics and Electronic Discovery
http://articles.forensicfocus.com/2012/12/09/windows-8-important-considerations-for-computer-forensics-and-electronic-discovery/

Windows 8 Forensics: USB Activity
http://cyberarms.wordpress.com/2012/08/14/windows-8-forensics-usb-activity/

Windows 8 Forensics: Recycle Bin
http://cyberarms.wordpress.com/2012/08/13/windows-8-forensics-recycle-bin/

Windows 8 Forensics: Internet History Cache
http://cyberarms.wordpress.com/2012/08/21/windows-8-forensics-internet-cache-history/

Windows 8.1 and Server 2012 R2 Still allow Login Bypass
http://cyberarms.wordpress.com/2013/08/10/windows-8-1-and-server-2012-r2-still-allow-login-bypass/

Windows 8 Clear Text Passwords from Locked Desktop with Mimikatz
http://cyberarms.wordpress.com/2012/11/10/windows-8-clear-text-passwords-from-locked-desktop-with-mimikatz/

Microsoft Forcing Users to use Less Secure Passwords?
http://cyberarms.wordpress.com/2012/09/07/microsoft-forcing-users-to-use-less-secure-passwords/

Windows 8 Forensics
http://forensicinsight.org/wp-content/uploads/2012/03/INSIGHT-Windows-8-Forensics.pdf

Windows 8: Tracking Opened Photos
http://dfstream.blogspot.jp/2013/03/windows-8-tracking-opened-photos.html

Windows 8 TypedURLsTime
http://dfstream.blogspot.jp/2012/05/windows-8-typedurlstime.html

□Introduction to Windows 8 Forensics
http://dig4n6.blogspot.jp/2012/06/introduction-to-windows-8-forensics.html

Windows 8 Forensics: Investigating the Recycle Bin
http://www.nightlionsecurity.com/blog/guides/2012/08/5055/#.UhLBvtIRLQo

Windows 8 and WinFE
http://winfe.wordpress.com/2012/08/22/windows-8-and-winfe/

□UserAssist Windows 2000 Thru Windows 8
http://blog.didierstevens.com/2012/07/19/userassist-windows-2000-thru-windows-8/

□Thumbcache Viewer
https://code.google.com/p/thumbcache-viewer/

Windows 8 Forensics
http://marketing.accessdata.com/acton/attachment/4390/f-03d3/1/-/-/-/-/file.pdf

Windows 8 Forensics - A First Look
http://www.forensicfocus.com/c/aid=49/

□Hiberfil.sys, Pagefile.sys & the New Swapfile.sys file in Windows 8
http://www.thewindowsclub.com/hiberfil-pagefile-swapfile-sys-windows

Internet Explorer 10 webcache JETblue database
http://www.forensicfocus.com/Forums/viewtopic/t=10434/

Internet Explorer Artifacts
http://www.cse.scu.edu/~tschwarz/COEN252_13/Labs/lab6.html

□Forensic analysis of the ESE database in Internet Explorer 10
http://www.diva-portal.org/smash/get/diva2:635743/FULLTEXT02

Microsoft Windows 8: A Forensic First Look
http://www.dfinews.com/articles/2012/09/microsoft-windows-8-forensic-first-look#.UhLI49IRLQo

□How to Recover and Interpret Internet Artifacts
http://thetrainingco.com/Techno-2013-PDF/TUESDAY/T6%20Saliba%20-%20Internet%20Artifact%20Autopsy.pdf

IE Password Decryptor
http://securityxploded.com/iepassworddecryptor.php

□My Windows 8 DFIR Reading List
http://davnads.blogspot.jp/2013/01/my-windows-8-dfir-reading-list.html

Windows 8 A Forensic First Look
http://www.forensicfocus.com/downloads/windows-8-forensics-josh-brunty.pdf