Evidence obtaining method, device and equipment supporting multiple operating systems and storage medium
An operating system and file system technology, applied in the fields of instruments, electrical digital data processing, hardware monitoring, etc., can solve the problem of no user trace analysis and image forensics methods, no support for offline and online forensics methods, and no way to know the computer operating system. What is the problem, to achieve the effect of convenient evidence collection
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2020-06-26
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The invention relates to the field of computer evidence collection, in particular to a method, device, equipment and storage medium supporting multiple operating systems. Background technique
[0002] With the increasing number of computer crime cases and the digitalization of crime methods, the work of collecting electronic evidence has become the key to providing important clues and solving cases.
[0003] At present, the online forensics methods for computers are all based on specific computer operating system types, and it is impossible to implement one method to support online and offline online forensics for computers with multiple operating systems. Therefore, in the face of on-site evidence collection, the forensics personnel need to carry various forensic tools, because it is impossible to know in advance what the computer operating system that the on-site evidence collection is facing is.
[0004] In a nutshell, the existing technology has t...
Examples
Embodiment Construction
[0050] The present invention is further illustrated below by means of examples, but the present invention is not limited to the scope of the examples.
[0051] First of all, the present invention proposes a forensic method supporting multiple operating systems, which is used to obtain evidence for operating systems through portable storage devices. The types of operating systems mentioned here mainly refer to Windows operating systems, macOS operating systems, and Linux operating systems. .
[0052] In the first embodiment, if figure 1 As shown, the described evidence collection method supporting multiple operating systems includes the following steps:
[0053] Step 01: Run the forensic collection system on the forensics object according to the startup instruction, the startup instruction includes a cold start instruction and a direct operation instruction, and the forensics system includes an offline forensics collection system and an online forensics collection system; if t...