Matt Bromiley has published a very useful post on forensic analysis of Volume Shadow Copies. You will learn about two types of shadow copies, mounting VSCs on live and dead systems, their traces in the Registry and analysis.

Load More Related Articles
Load More In How To

Leave a Reply

Your email address will not be published. Required fields are marked *