Messing with Forensic Analysts - Modifying VSS Snapshots

Messing with Forensic Analysts - Modifying VSS Snapshots

BSidesLV via YouTube Direct link

How to tell if a snapshot has been modified

16 of 19

16 of 19

How to tell if a snapshot has been modified

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Messing with Forensic Analysts - Modifying VSS Snapshots

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 What is VSS
  3. 3 Basics of VSS
  4. 4 Why should you care
  5. 5 Examples
  6. 6 Documentation
  7. 7 On Disk Format
  8. 8 NTFS Header
  9. 9 What is in a Store
  10. 10 Data Block List
  11. 11 Example Snapshot
  12. 12 Writing Data to a Snapshot
  13. 13 Block Descriptors
  14. 14 The Really Good Stuff
  15. 15 Demo
  16. 16 How to tell if a snapshot has been modified
  17. 17 Hardest way to find out
  18. 18 Modify timestamps
  19. 19 Questions

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.