tools for malware forensics

Hi,

I did a lot of searches in technet forums and with google but still missing some clear statements:

I like to see the footprint in terms of a list of files and registry entries of a software install or what ever, e.g. malware or browsing session.

1-2 decades ago this was done by sysdiff, which scans the hard disk and compares it simply on application level.

now in 2015 we have VSS feature for the file system and virtualPC, hyper-v and more and snapshots, differencing disks and VM states.

Which is these new features is helping to speed up finding these diff between two times of a windows system (desktop)? I thought there would be a snapdiff tool or sth. but I did not find...

thanks in advance

A.


  • Edited by Alex_2015 Tuesday, April 28, 2015 8:21 AM
April 28th, 2015 8:20am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics