LNK file analysis with EnCase forensic

In our previous recipes, you have already learnt how to create a new case, add evidence files, and examine Windows recycle bin contents with EnCase Forensic. Now it's time to go even further, and meet the EnCase Evidence Processor, and especially the Windows Artifact Parser. This module enables a digital forensic examiner to parse different Windows forensic artifacts, including LNK files, automatically.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.191.43.140