Forensic analysis of Windows 10 Sandbox

stručni rad

stručni rad

Forensic analysis of Windows 10 Sandbox

Vrsta prilog sa skupa (u zborniku)
Tip stručni rad
Godina 2020
Nadređena publikacija MIPRO 2020 : 43rd International Convention : Proceedings
Stranice str. 1224-1229
DOI 10.23919/MIPRO48935.2020.9245226
ISSN 1847-3946
Status objavljeno

Sažetak

With each Windows operating system Microsoft introduces new features to its users. Newly added features present a challenge to digital forensics examiners as they are not analyzed or tested enough. One of the latest features, introduced in Windows 10 version 1909 is Windows Sandbox ; a lightweight, temporary, environment for running untrusted applications. Because of the temporary nature of the Sandbox and insufficient documentation, digital forensic examiners are facing new challenges when examining this newly added feature which can be used to hide different illegal activities. Throughout this paper, the focus will be on analyzing different Windows artifacts and event logs, with various tools, left behind as a result of the user interaction with the Sandbox feature on a clear virtual environment. Additionally, the setup of testing environment will be explained, the results of testing and interpretation of the findings will be presented, as well as open-source tools used for the analysis.

Ključne riječi

Windows 10; Sandbox; digital forensics