Professional Documents
Culture Documents
Lab 6 Windows Forensics
Lab 6 Windows Forensics
Lab 6 Windows Forensics
Task 1: Use Windows Event Viewer to audit failed Login + cleared logs:
1- First try to type the wrong password in Login, then try again with
correct credentials.
2- Open Event Viewer app.
Volume Shadow Copy Service or VSS is a technology included in Microsoft Windows that allows
taking manual or automatic backup copies or snapshots of computer files or volumes, even when
they are in use.
1- We need to enable (system restore )on Windows VM. In the search bar type system
Protection.
4- Choose Turn on system protection>>move the cursor in Max Usage to specify the volume
size>>Apply>> Ok