Evidence collection methods and devices

By modifying the login verification command of the system hibernation file in the computer hibernation state and logging in with any password, the problem of not being able to unlock the lock screen computer to obtain running data, and the successful completion of evidence forensics is achieved.

CN114491503BActive Publication Date: 2025-08-12QIAN PANGU (SHANGHAI) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111547392.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-16
Publication Date
2025-08-12
Estimated Expiration
2041-12-16

AI Technical Summary

Technical Problem

When the computer is in a locked state and cannot be unlocked with a password, it is difficult to obtain the current system running data in physical memory as evidence.

Method used

By modifying the login verification instructions in the system sleep file with the second system while the first system is in a sleep state, and logging in to the system with any password, accessing the running data before the system sleep state.

Benefits of technology

It realizes that the system's current running data is successfully obtained when the computer cannot be unlocked, and supports forensic analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491503B_ABST
    Figure CN114491503B_ABST
Patent Text Reader

Abstract

The present application provides a forensic method and device, which includes: when the first system is in a dormant state, modifying the login verification instruction in the system dormant file of the first system through a second system; using any random password to log in to the first system and access the system operation data before the first system enters the dormant state; wherein the second system is the operating system running on the device running the first system after the first system enters the dormant state; the login verification instruction is used to verify the login password of the first system. The forensic method and device provided in the embodiments of the present application are used to complete the forensics of the current system operation data when the computer in the locked state cannot be unlocked by the password.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of evidence collection, and in particular to a method and device for collecting evidence. Background Art

[0002] The information stored in a computer's physical memory records various status information during the current system operation, such as progress information, network connection information, files being accessed, web pages being browsed, etc. During the forensic process, this status information is as important as the information stored on the hard drive.

[0003] However, since the information stored in the physical memory disappears when the system is shut down, if the computer is in a locked state during on-site evidence collection and it is impossible to unlock the computer and enter the system using a password, it is difficult to preserve the information stored in the physical memory as evidence. Summary of the Invention

[0004] The purpose of this application is to provide a forensics method and device for obtaining evidence of the current running data of the system when a computer in a locked state cannot be unlocked by a password.

[0005] This application provides a method for obtaining evidence, including:

[0006] When a first system is in a dormant state, a login verification instruction in a system dormant file of the first system is modified through a second system; any random password is used to log in to the first system, and system operation data before the first system enters the dormant state is accessed; wherein, the second system is an operating system running on a device running the first system after the first system enters the dormant state; the login verification instruction is used to verify the login password of the first system.

[0007] Optionally, when the first system is in a dormant state, before modifying the login verification instruction in the system dormant file of the first system through the second system, the method also includes: when the first system is in a locked screen state, controlling the first system to enter a dormant state; wherein, after the first system receives the control instruction to enter the dormant state, the first login verification instruction of the first system is stored in the system dormant file, and after recovering from the dormant state, the login password is verified based on the first login verification instruction.

[0008] Optionally, when the first system is in a dormant state, the login verification instruction in the system dormant file of the first system is modified by the second system, including: when the first system is in a dormant state, loading the second system; after the second system is successfully loaded, modifying the first login verification instruction in the system dormant file to a second login verification instruction.

[0009] Optionally, using any random password to log in to the first system and accessing the system operation data before the first system enters the sleep state includes: restoring the first system from the sleep state and using any random password to log in to the first system; if the first system is successfully logged in, accessing the system operation data of the first system.

[0010] Optionally, after using any random password to log in to the first system and accessing the system operation data before the first system enters the sleep state, the method also includes: controlling the first system to enter the sleep state and loading the second system; after the second system is successfully loaded, modifying the second login verification instruction in the system sleep file of the first system to the first login verification instruction; and restoring the first system from the sleep state.

[0011] This application also provides a forensics device, comprising:

[0012] A modification module is used to modify the login verification instruction in the system hibernation file of the first system through the second system when the first system is in hibernation; a forensics module is used to log in to the first system using any random password and access the system operation data before the first system enters the hibernation state; wherein, the second system is the operating system running on the device running the first system after the first system enters the hibernation state; the login verification instruction is used to verify the login password of the first system.

[0013] Optionally, the device also includes: a control module; the control module is used to control the first system to enter a sleep state when the first system is in a locked state; wherein, after the first system receives the control instruction to enter the sleep state, the first login verification instruction of the first system is stored in the system sleep file, and after recovering from the sleep state, the login password is verified based on the first login verification instruction.

[0014] Optionally, the modification module is specifically used to load the second system when the first system is in a dormant state; the modification module is also specifically used to modify the first login verification instruction in the system dormant file to a second login verification instruction after the second system is successfully loaded.

[0015] Optionally, the evidence collection module is specifically used to restore the first system from a dormant state and log in to the first system using any random password; the evidence collection module is also specifically used to access the system operation data of the first system when the first system is successfully logged in.

[0016] Optionally, the control module is also used to control the first system to enter a sleep state and load the second system; the modification module is also used to modify the second login verification instruction in the system sleep file to the first login verification instruction after the second system is successfully loaded; the control module is also used to restore the first system from a sleep state.

[0017] The present application also provides a computer program product, comprising a computer program / instruction, which implements the steps of any of the forensic methods described above when executed by a processor.

[0018] The present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any of the forensic methods described above when executing the program.

[0019] The present application also provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of any of the forensic methods described above when executed by a processor.

[0020] The evidence collection method and device provided in this application can, when a locked computer cannot be unlocked using a login password, control the computer's first system to enter a dormant state. While the first system is in dormant, a second system can modify the login verification instructions in the first system's system dormant file. Subsequently, a random password can be used to log in to the first system and access the system operating data before the first system entered dormant state, thereby completing the evidence collection of the system's current operating data. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0022] Figure 1 It is a flowchart of the evidence collection method provided by this application;

[0023] Figure 2 This is a schematic diagram of the production process of the USB boot tool provided by this application;

[0024] Figure 3 This is a flowchart of modifying the login password of the first system provided by this application;

[0025] Figure 4 This is a flowchart of restoring the login password of the first system provided by this application;

[0026] Figure 5 It is a structural diagram of the evidence collection device provided by this application;

[0027] Figure 6 It is a structural diagram of the electronic device provided in this application. DETAILED DESCRIPTION

[0028] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.

[0029] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type, and do not limit the number of objects; for example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.

[0030] Currently, when collecting evidence on-site, if the computer is in the locked state and cannot be unlocked with the login password, the evidence collector cannot log in to the computer system and obtain the current system operation data. This operation data is stored in the computer's physical memory.

[0031] Memory, also known as internal memory or main memory, is a crucial component of a computer. It temporarily stores computational data from the central processing unit (CPU) and exchanges data with external storage devices such as hard drives. It serves as the bridge between external storage and the CPU, and all computer programs run in memory. Because data stored in memory completely disappears upon power failure, it is difficult to obtain the system's current operating data and conduct forensic analysis without unlocking the computer.

[0032] Based on this, this application provides a method to retain the computer's running data and bypass the computer's login password, solving the problem that forensic personnel cannot obtain the data running on the computer in the locked screen state. It can enable forensic personnel to maximize the acquisition of on-site computer electronic data, and provide strong support for computer forensic analysis and the discovery of clues and traces.

[0033] The following describes in detail the evidence collection method provided by the embodiment of the present application through specific embodiments and their application scenarios in conjunction with the accompanying drawings.

[0034] like Figure 1 As shown, an embodiment of the present application provides a method for obtaining evidence, which may include the following steps 101 and 102:

[0035] Step 101: When a first system is in a dormant state, a login verification instruction in a system dormant file of the first system is modified by a second system.

[0036] The second system is an operating system running on a device running the first system after the first system enters a dormant state; the login verification instruction is used to verify a login password for the first system.

[0037] It is understandable that the above login verification instruction can verify the login password when the user logs in using the login password. By modifying the login verification instruction, the user can successfully log in to the system by entering any password, thereby achieving the purpose of bypassing the login password.

[0038] For example, the first system may be a Windows system, and the second system may also be a Windows system, or a Windows Preinstallation Environment (PE) system. After the first system enters hibernation, the second system may be started through a boot program of a Basic Input Output System (BIOS), and after successful startup, access the system hibernation file Hiberfil.sys of the first system stored in the hard disk.

[0039] For example, when the first system enters a dormant state, the system operating data of the first system before entering the dormant state is stored in the above-mentioned system dormant file, such as the system login verification instructions. Based on this, the embodiment of the present application contemplates that by modifying the login verification instructions stored in the system dormant file of the first system, it is possible to log in to a computer in a locked state and obtain the current operating data of the computer system.

[0040] Step 102: Use any random password to log in to the first system and access the system operation data before the first system enters the dormant state.

[0041] Exemplarily, any of the above random passwords may be any password, including passwords of randomly combined numbers, letters, characters, and the like.

[0042] For example, after entering the second system and modifying the login authentication instructions stored in the system hibernation file of the first system, upon restarting the computer, the computer memory will automatically read the modified system hibernation file and restore the first system to its pre-hibernation state. Afterwards, any random password can be used to log in to the first system, thereby enabling access to the system operation data before the first system entered the hibernation state. For example, using any password to access the desktop of the first system, you can view the operations currently being performed on the first system or the content being accessed.

[0043] In this way, when a locked computer cannot be unlocked using the login password, the computer's first system can be controlled to enter a dormant state. While the first system is in dormant, the second system can modify the login verification instructions in the first system's system dormant file. Afterwards, any random password can be used to log in to the first system and access the system operating data before the first system entered the dormant state, thereby completing the forensics of the system's current operating data.

[0044] Optionally, in an embodiment of the present application, in order to store the current system running data of the first system into the system hibernation file, it is necessary to control the first system in the locked screen state to enter the hibernation state.

[0045] For example, before the above step 101, the evidence collection method provided in the embodiment of the present application may further include the following step 103:

[0046] Step 103: When the first system is in a locked screen state, control the first system to enter a sleep state.

[0047] After receiving the control instruction to enter the sleep state, the first system stores the first login verification instruction of the first system in the system sleep file, and verifies the login password based on the first login verification instruction after recovering from the sleep state.

[0048] For example, the first system may be controlled to enter the sleep state by using a sleep button on the computer host, or by clicking a sleep button in the power options on the lock screen interface to control the first system to enter the sleep state.

[0049] It should be noted that when the first system receives the control instruction to enter the hibernation state, it will store the system operation data of the first system in the system hibernation file. When the first system resumes from the hibernation state, it will reload the system operation data from the system hibernation file into the memory, thereby restoring the system to the operating state before entering the hibernation state.

[0050] For example, when the first system enters the dormant state, the second system can be started by the BIOS boot program. The second system can be another operating system in the computer that is different from the first system, or an operating system stored in an external storage medium (e.g., a USB flash drive).

[0051] It is understood that after the first system enters sleep mode, when the user presses the computer's power button, the computer can restart the first system or boot the computer through another system. The computer to be used for evidence collection may only have a single operating system installed. To facilitate evidence collection, a pre-made USB boot tool can be used. When evidence collection is required, the USB boot tool can be inserted into the computer to be used and the system installed on the USB boot tool, i.e., the second system, can be booted.

[0052] For example, the present application embodiment is explained by taking the example of starting the computer through a USB disk. Figure 2 The figure shows a flowchart of the U disk boot tool production process. First, you need to prepare a U disk, Windows system firmware and a U disk boot tool burning program. Afterwards, use the U disk boot tool burning program to burn the Windows system firmware into the U disk, make a customized U disk device, and obtain a U disk boot tool that can be used as a boot tool. In order to be able to modify the system hibernation file of the first system, a hibernation file data modification program is also added to the above-mentioned Windows system firmware. After the computer starts the Windows system in the U disk through the U disk boot tool, the system hibernation file of the first system can be modified through the hibernation file data modification program. Specifically, the login verification instruction in the system hibernation file can be modified to achieve the purpose of bypassing the login password.

[0053] For example, after obtaining the above-mentioned U disk startup tool, the Windows system burned into the U disk can be started by guiding the U disk startup tool through BIOS after the first system enters the dormant state.

[0054] Illustratively, the above step 101 may include the following steps 101a1 and 101a2:

[0055] Step 101a1: When the first system is in a dormant state, load the second system.

[0056] Step 101a2: After the second system is loaded successfully, the first login verification instruction in the system hibernation file is modified into a second login verification instruction.

[0057] It can be understood that the second system mentioned above is the Windows system burned in the above-mentioned USB flash drive startup tool.

[0058] For example, after the first system enters the hibernation state, the computer may load the second system and modify the login verification instruction in the system hibernation file of the first system through the hibernation file data modification program in the second system.

[0059] It is understandable that when the first system enters the hibernation state and loads the second system, the second system can access any resource of the first system on the hard disk, including the system hibernation file of the first system.

[0060] It can be understood that in order to restore the computer that needs to be collected for evidence to its original state after the evidence collection is completed, the first login verification instruction of the first system can be saved when the first login verification instruction is modified, and after the evidence collection is completed, the login password of the first system can be restored to the original password through the first login verification instruction.

[0061] For example, after the login password of the first system is changed, the above step 102 may include the following steps 102a1 and 102a2:

[0062] Step 102a1: Restore the first system from a dormant state, and log in to the first system using any random password.

[0063] Step 102a2: When the first system is successfully logged in, access the system operation data of the first system.

[0064] For example, Figure 3 The figure shows a flow chart of modifying the login password of the first system provided by the embodiment of the present application. Figure 2After making a customized U disk device according to the steps in, the evidence collector inserts the prepared U disk boot tool into the computer in the locked screen state. After controlling the computer in the locked screen state to sleep, start the computer. It should be noted that the computer needs to be set to boot from the U disk, so that the computer can directly start the Windows system in the U disk (that is, the above-mentioned second system) when it starts. Afterwards, enter the Windows system, run the hibernation file modification program, and modify the login verification information in the system hibernation file of the original computer's original system (that is, the above-mentioned first login verification instruction). After the modification is completed, restart the computer, enter the lock screen interface of the original locked screen computer system (that is, the above-mentioned first system), enter any password, enter the original locked screen computer desktop, and complete the evidence collection.

[0065] It is understood that after the first system resumes from the hibernation state, any random password can be used to log in to the first system and access the system operation data before the first system entered the hibernation state. For example, before the first system entered the hibernation state, the first system was accessing website A. After the first system enters the hibernation state and resumes from the hibernation state, the accessed website A can still be displayed.

[0066] For example, after completing the evidence collection, if you want to restore the computer whose evidence is collected to its original state, for example, restore the login password of the first system to the original login password, you need to save the modified original information in the system hibernation file and replace the modified information with the saved original information.

[0067] For example, after step 102, the evidence collection method provided in the embodiment of the present application may further include the following steps 104 to 106:

[0068] Step 104: Control the first system to enter a dormant state and load the second system.

[0069] Step 105: After the second system is loaded successfully, the second login verification instruction in the system hibernation file is modified to the first login verification instruction.

[0070] Step 106: Restore the first system from the dormant state.

[0071] For example, when modifying the system hibernation file of the first system, the modified information needs to be backed up. After the evidence collection is completed, the backed-up information is used for restoration to restore the computer to the state before the evidence collection.

[0072] For example, Figure 4 The figure shows the process of recovering the login password of the first system. After the evidence is collected, the first system is controlled to enter the dormant state. Figure 3The method for modifying the login verification information shown is to restore the login password of the first system. Specifically, the Windows system in the USB boot tool is started, the hibernation file modification program in the Windows system is run, and the modified second login verification instruction is replaced with the first login verification instruction in the original system hibernation file to restore the original computer password.

[0073] The forensic collection method provided in an embodiment of the present application, when evidence collection is required on a locked computer and the computer cannot be unlocked using the login password, controls the computer's first system to enter a hibernation state. Subsequently, a second system, using a USB boot tool, is booted. After the second system successfully boots, the login verification information in the first system's system hibernation file is modified using a hibernation file modification program in the second system, thereby changing the first system's login password to a random password. Finally, the first system is logged in using the random password, completing the forensic collection of the system's operating data before the first system entered the hibernation state.

[0074] It should be noted that the evidence collection method provided in the embodiments of the present application can be executed by a forensic device or a control module in the forensic device for executing the forensic method. In the embodiments of the present application, the forensic device executing the forensic method is used as an example to illustrate the forensic device provided in the embodiments of the present application.

[0075] It should be noted that in the embodiments of this application, the forensic methods shown in the figures of the above-mentioned methods are all described by way of example in conjunction with one of the figures in the embodiments of this application. In specific implementation, the forensic methods shown in the figures of the above-mentioned methods can also be implemented in conjunction with any other combinable figures shown in the above-mentioned embodiments, and will not be further described here.

[0076] The evidence collection device provided in this application is described below, and the evidence collection method described below can be referenced to each other with the evidence collection method described above.

[0077] Figure 5 The schematic diagram of the structure of the evidence collection device provided in the embodiment of the present application is as follows: Figure 5 As shown, it specifically includes: a modification module 501, which is used to modify the login verification instruction in the system hibernation file of the first system through the second system when the first system is in a dormant state; a forensics module 502, which is used to use any random password to log in to the first system and access the system operation data before the first system enters the dormant state; wherein, the second system is the operating system running on the device running the first system after the first system enters the dormant state; the login verification instruction is used to verify the login password of the first system.

[0078] Optionally, the device also includes: a control module; the control module is used to control the first system to enter a sleep state when the first system is in a locked state; wherein, after the first system receives the control instruction to enter the sleep state, the first login verification instruction of the first system is stored in the system sleep file, and after recovering from the sleep state, the login password is verified based on the first login verification instruction.

[0079] Optionally, the modification module 501 is specifically used to load the second system when the first system is in a dormant state; the modification module 501 is also specifically used to modify the first login verification instruction in the system dormant file to a second login verification instruction after the second system is successfully loaded.

[0080] Optionally, the evidence collection module 502 is specifically used to restore the first system from a dormant state and log in to the first system using any random password; the evidence collection module 502 is also specifically used to access the system operation data of the first system when the first system is successfully logged in.

[0081] Optionally, the control module is also used to control the first system to enter a sleep state and load the second system; the modification module 501 is also used to modify the second login verification instruction in the system sleep file to the first login verification instruction after the second system is successfully loaded; the control module is also used to restore the first system from a sleep state.

[0082] The evidence collection device provided in this application, when evidence collection is required on a locked computer and the computer cannot be unlocked using the login password, controls the computer's first system to enter a dormant state. It then boots up a second system using a USB boot tool. After the second system successfully boots up, it uses a dormant file modification program in the second system to modify the login verification information in the first system's dormant file, changing the first system's login password to a random password. Finally, the first system is logged in using the random password, completing the evidence collection of the system's operating data before the first system entered the dormant state.

[0083] Figure 6 An example of a physical structure diagram of an electronic device is shown below. Figure 6As shown, the electronic device may include: a processor (processor) 610, a communication interface (Communications Interface) 620, a memory (memory) 630 and a communication bus 640, wherein the processor 610, the communication interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 can call the logic instructions in the memory 630 to execute the forensics method, which includes: when the first system is in a dormant state, modifying the login verification instruction in the system dormant file of the first system through the second system; using any random password to log in to the first system and access the system operation data before the first system enters the dormant state; wherein the second system is the operating system running on the device running the first system after the first system enters the dormant state; the login verification instruction is used to verify the login password of the first system.

[0084] In addition, the logic instructions in the above-mentioned memory 630 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0085] On the other hand, the present application also provides a computer program product, which includes a computer program stored on a computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the forensic method provided by the above methods, and the method includes: when the first system is in a dormant state, modifying the login verification instruction in the system dormant file of the first system through a second system; using any random password to log in to the first system, and accessing the system operation data before the first system enters the dormant state; wherein, the second system is an operating system running on a device running the first system after the first system enters the dormant state; the login verification instruction is used to verify the login password of the first system.

[0086] On the other hand, the present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the above-mentioned forensic methods, the method comprising: when the first system is in a dormant state, modifying the login verification instruction in the system dormant file of the first system through a second system; using any random password to log in to the first system, and accessing the system operation data before the first system enters the dormant state; wherein, the second system is an operating system running on a device running the first system after the first system enters the dormant state; the login verification instruction is used to verify the login password of the first system.

[0087] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0088] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.

[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for obtaining evidence, characterized in that: include: When the first system is in a dormant state, modifying, by the second system, a login verification instruction in the system dormancy file Hiberfil.sys of the first system stored in the hard disk; Use any random password to log in to the first system and access the system operation data before the first system enters the dormant state; The second system is an operating system running on a device running the first system after the first system enters a dormant state; the login verification instruction is used to verify the login password of the first system; after the first system receives the control instruction to enter a dormant state, the first system stores the first login verification instruction of the first system in the system dormant file, and after resuming from the dormant state, verifies the login password based on the first login verification instruction; When the first system is in a dormant state, modifying the login verification instruction in the system dormant file of the first system by the second system includes: When the first system is in a dormant state, loading the second system; After the second system is loaded successfully, the first login verification instruction in the system hibernation file is modified into a second login verification instruction.

2. The method according to claim 1, characterized in that Before modifying the login verification instruction in the system hibernation file of the first system by the second system when the first system is in the hibernation state, the method further includes: When the first system is in a locked state, control the first system to enter a sleep state.

3. The method according to claim 1, characterized in that The step of using any random password to log in to the first system and accessing the system operation data before the first system enters the dormant state includes: Resuming the first system from a dormant state and logging into the first system using any random password; When the user successfully logs into the first system, the user accesses the system operation data of the first system.

4. The method according to claim 1, wherein After logging into the first system using any random password and accessing the system operation data before the first system enters the dormant state, the method further includes: Controlling the first system to enter a dormant state and loading the second system; After the second system is successfully loaded, the second login verification instruction in the system hibernation file is modified to the first login verification instruction; Resuming the first system from a hibernation state.

5. A forensics device, characterized in that: The device comprises: a modification module, configured to modify, by the second system, a login verification instruction in a system hibernation file Hiberfil.sys of the first system stored in the hard disk when the first system is in a dormant state; a forensics module, configured to log into the first system using any random password and access system operation data before the first system enters a dormant state; The second system is an operating system running on a device running the first system after the first system enters a dormant state; the login verification instruction is used to verify the login password of the first system; after the first system receives the control instruction to enter a dormant state, the first system stores the first login verification instruction of the first system in the system dormant file, and after resuming from the dormant state, verifies the login password based on the first login verification instruction; The modification module is specifically configured to load the second system when the first system is in a dormant state; The modification module is further configured to modify the first login verification instruction in the system hibernation file into a second login verification instruction after the second system is successfully loaded.

6. The device according to claim 5, characterized in that The device further includes: a control module; The control module is configured to control the first system to enter a dormant state when the first system is in a locked screen state; After receiving the control instruction to enter the sleep state, the first system stores the first login verification instruction of the first system in the system sleep file, and verifies the login password based on the first login verification instruction after recovering from the sleep state.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the evidence collection method according to any one of claims 1 to 4 are implemented.

8. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the evidence collection method according to any one of claims 1 to 4 are implemented.