zoukankan      html  css  js  c++  java
  • Can Live View boot up images acquired from 64bit OS evidence?

    Some said Live View could only boot up images acquired from 32bit OS evidence. I have to say that it's not true. Ok, the best way to prove it is let the evidence speak for themselves~

    1. Boot up Windows 7 64bit evidence

    2. Live View boot up Linux 64bit evidence

    I think the reason why some forensic guys "believe" that Live View could not boot evidence suessfully are as below:

    1.They forgot mounting tools(ex: FTK Imager) requires Administrator privileges to run.

    2.They forgot Live View requires Administrator privileges to run.

    3.Whenever they saw any terrible word(ike "error","warning","failed") in the Live View message boxs, they will shut Live View down immediately without hesitate. Acutally they should be more patient, let Live View to parse and analyze those partitions. When completed they could use VMWare to open the snapshot and see if it works or not. Remember one very important thing : "Don't jump to conclusions too soon"...some forensics should get rid of such kind of bad habit...

    It's an Open Source Java-based solution. You guys could take a look at it's website and forums:

    http://liveview.sourceforge.net/index.html

    http://sourceforge.net/p/liveview/discussion/

    By the way, VFC is a commercial solution. In my experience, Live View is better than VFC. Of course it's not 100% guarantee to boot up evidence with Live View(or VFC). Still you have chances fail to boot up and see Blue Death screen...

  • 相关阅读:
    Scrum:The Definition of Done —— 作业有没有写完呢?
    中兴通讯 可视化devops 牛啊 屠亚奇
    qunar-dns
    通过业务系统的重构实践DDD
    通过业务系统的重构实践DDD
    一键部署Kubernetes高可用集群
    springboot系列
    Ubuntu · Docker —— 从入门到实践
    容器化操作系统概览
    基于 CentOS7 的 Kubernetes 集群
  • 原文地址:https://www.cnblogs.com/pieces0310/p/4677987.html
Copyright © 2011-2022 走看看