×

HYPERVISOR-HOSTED VIRTUAL MACHINE FORENSICS

  • US 20160034295A1
  • Filed: 07/22/2015
  • Published: 02/04/2016
  • Est. Priority Date: 07/30/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer system configured to acquire forensics data from running virtual machines, the computer system comprising:

  • a processor configured to execute computer-executable instructions; and

    memory storing computer-executable instructions configured to;

    run a hypervisor that hosts a virtualization environment including a root virtual machine partition and one or more child virtual machine partitions;

    provide a forensics partition that includes a forensics service application programming interface configured to target one or more virtual machines and acquire forensics data from a targeted virtual machine running in a particular child virtual machine partition via one or more inter-partition communication mechanisms supported by the virtualization environment hosted by the hypervisor; and

    expose the forensics service application programming interface to a forensics tool as part of a cloud-based forensics service.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×