Cyber Securities Technology Logo Next-generation software for computer investigations of live computers inenterprises
Photo

Tour Background
1. Logging into OnLineDFS
2. Creating an inquiry
3. Logging into the target system
4. The initial acquisition
5. Analyzing data
6. Acquiring state data
7. Acquiring files
8. Displaying data
9. Continuing the investigation
10. Logging out

OnLineDFS: A Guided Tour


Background | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10

5. Analyzing Data (continued) <-- Previous Next -->

Miller is interested in the processes and programs that Wallace is running on his machine. It's possible that Wallace is running some illicit programs to carry out the suspected credit card theft. Miller decides to examine the most recently started programs first, as they are the most likely to be used for illicit purposes. Longer running processes are more likely to be system processes used for legitimate purposes. On the Running Processes screen, shown in Figure 10, he clicks (twice) on the words "Start Time" at the top of the last column in order to sort by that column in descending order.

Figure 10 - Running Processes
Figure 10 - Running Processes

Back to top <-- Previous Next -->