×

System and Method for Forensic Identification of Elements Within a Computer System

  • US 20100030996A1
  • Filed: 08/01/2008
  • Published: 02/04/2010
  • Est. Priority Date: 08/01/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method of forensically analyzing data comprising:

  • accessing a plurality of values representing data contained within a memory of a computer system;

    searching the plurality of values for a first identifying characteristic that indicates an operating system;

    upon finding the first identifying characteristic, searching for a second characteristic that indicates an operating system;

    analyzing the distance within the memory of the computer system between the first identifying characteristic and the second identifying characteristic; and

    determining, from the distance, a type and a version of an operating system loaded into the computer system'"'"'s memory.

View all claims
  • 11 Assignments
Timeline View
Assignment View
    ×
    ×