0
984views
Explain areas of OS which are beneficial for Incidence Response investigation.

Subject: Digital Forensics

Topic: Preserving and Recovering Digital Evidence

Difficulty: Medium

1 Answer
0
2views

In windows system, log files are the best source to collect information of incident. The most important upgrade logs are setupact.log and setuperr.log which you find in different locations depending on the upgrade stage. The two important log files setupact.log and setuperr.log use the following format:

• Date and time.

• Log Level (Info, Warning, Error, Fatal Error)

• Logging Component (CONX, MOUPG, PANTHR, SP, IBSLIB, MIG, DISM, CSI, CBS)

• Message

Windows Log file locations are as follows (open Event Viewer) –

• Application

• Security

• Setup

• System

• Forwarded events

• Application and service logs

All log file locations contain different log files as

Please log in to add an answer.