Analysis of Windows 11 Link File Artifact for Evidence Gathering
At a glance
- الاستشهادات
- 0
- المراجع
- 14
- Comments
- 0
Abstract
The objects created by the operating system are known as artifacts, and they contain crucial data about the actions taken by computer users. Thus, these artifacts are of great relevance to the forensic analyst. These artifacts can act as a evidence in a court of law to prove the digital crime. Link File or Shortcut file is one such object, presence of which confirms the usage of file in recent time. Link File are links between the executable and the applications. In this work, Link File is forensically analyzed and bring out its forensic value, knowledge it provides and perform few in-depth forensics examinations on Link File useful for analyst using open source FTK Imager tool. Lastly, we compared the Link File artifacts in various versions of Windows Operating System
Publication details
- DOI
- 10.1109/incoft55651.2022.10094555
- OpenAlex
- W4365788332
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.