共 18 条
[4]
Extracting Windows command line details from physical memory[J] . Richard M. Stevens,Eoghan Casey.Digital Investigation . 2010
[5]
A second generation computer forensic analysis system[J] . Daniel Ayers.Digital Investigation . 2009
[6]
Using shellbag information to reconstruct user activities[J] . Yuandong Zhu,Pavel Gladyshev,Joshua James.Digital Investigation . 2009
[7]
A comparative methodology for the reconstruction of digital events using windows restore points[J] . Yuandong Zhu,Joshua James,Pavel Gladyshev.Digital Investigation . 2009 (1)
[8]
Recovering deleted data from the Windows registry[J] . Timothy D. Morgan.Digital Investigation . 2008
[9]
FACE: Automated digital evidence discovery and correlation[J] . Andrew Case,Andrew Cristina,Lodovico Marziale,Golden G. Richard,Vassil Roussev.Digital Investigation . 2008
[10]
A proposal for an integrated memory acquisition mechanism[J] . Eugene Libster,Jesse D. Kornblum.ACM SIGOPS Operating Systems Review . 2008 (3)