Title
Real-Time Forensics Through Endpoint Visibility
Abstract
In the course of the last years, there has been an established forensic process in place known by every investigator and researcher. This traditional process is regarded to produce valid evidence when it comes to court trials and, more importantly, it specifies on a very precise level how to acquire a suspects machine and handle the data within. However, when new technologies come into play, certain constraints appear: Having an incident in a network containing thousands of machines, like a global corporate network, there is no such thing as shutting down and sending an investigation team. Moreover, the question appears: Is this an isolated incident, or are there any other clients affected?
Year
DOI
Venue
2017
10.1007/978-3-319-73697-6_2
international conference on digital forensics
DocType
Citations 
PageRank 
Conference
0
0.34
References 
Authors
10
5
Name
Order
Citations
PageRank
Peter Kieseberg118729.39
Sebastian Neuner2736.06
Sebastian Schrittwieser329135.16
Martin Schmiedecker4221.65
Edgar Weippl52010.62