2017
DOI: 10.1111/1556-4029.13393
|View full text |Cite
|
Sign up to set email alerts
|

Windows 7 Antiforensics: A Review and a Novel Approach

Abstract: In this paper, we review literature on antiforensics published between 2010 and 2016 and reveal the surprising lack of up-to-date research on this topic. This research aims to contribute to this knowledge gap by investigating different antiforensic techniques for devices running Windows 7, one of the most popular operating systems. An approach which allows for removal or obfuscation of most forensic evidence is then presented. Using the Trojan software DarkComet RAT as a case study, we demonstrate the utility … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3

Citation Types

0
0
0

Year Published

2017
2017
2024
2024

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 6 publications
(3 citation statements)
references
References 43 publications
0
0
0
Order By: Relevance
“…Eterovic-Soric et al [172] point out the paucity of research on techniques that hinder digital forensic analysis of electronic devices, focusing specifically on Windows 7 computers. They propose a method that removes or hides much of the digital evidence that forensic analysts typically use in their investigations.…”
Section: Weaknesses and Anti-forensic Use Cases In Operating Systemsmentioning
confidence: 99%
See 2 more Smart Citations
“…Eterovic-Soric et al [172] point out the paucity of research on techniques that hinder digital forensic analysis of electronic devices, focusing specifically on Windows 7 computers. They propose a method that removes or hides much of the digital evidence that forensic analysts typically use in their investigations.…”
Section: Weaknesses and Anti-forensic Use Cases In Operating Systemsmentioning
confidence: 99%
“…Article [171] focuses on anti-forensics techniques for swap files, proposing two methods: fake data injection and creation of fake swap files. Article [172] discusses the lack of recent research on anti-forensics and proposes a general approach to hiding evidence on Windows 7 systems using Trojan software.…”
Section: Weaknesses and Anti-forensic Use Cases In Operating Systemsmentioning
confidence: 99%
See 1 more Smart Citation