论文部分内容阅读
提取360杀毒软件的进程历史日志进行取证分析,对公安机关刻画犯罪嫌疑人的行为特征有重要意义。阐述了如何借助360杀毒软件的进程历史日志准确地对用户行为进行分析取证的方法。通过360杀毒软件的历史进程日志可以还原Office文件编辑过程的时间节点、计算机系统开关机记录以及用户进程的运行状态,从而提取到与犯罪嫌疑人行为特征相关的线索。
The process of extracting 360 antivirus software history log forensic analysis of the public security agencies to characterize the behavior of suspects is of great significance. Elaborated on how to use 360 anti-virus software process history log accurately analyze the user’s behavior to obtain evidence. Through 360 anti-virus software history process log can restore the Office file editing process time node, the computer system switch machine records and the user process running status, so as to extract the suspect behavior characteristics related to the clues.