Section 5.1: Anti-Forensics Overview Flashcards
1
Q
What is the general use of anti-forensics techiniques?
A
To hide malware and activity.
2
Q
Anti-forensic techniques that happen on the filesystem:
A
Timestomping, fileless malware, data encryption, file deletion, and free space wiping.
3
Q
Anti-forensics techniques that happen at the registry:
A
Registry key/value deletion or wiping. Hiding scripts inside the registry.
4
Q
Other types of anti-forensics:
A
Event log deletion or tampering, process evasion such as rootkits or code injection.