A forensic device allows a user to remotely interrogate a target computing
device in order to collect and analyze computer evidence that may be
stored on the target computing device. The forensic device acquires the
computer evidence from the target computing device and filters the
computer evidence using an application-specific system-level privilege
profile that describes the aggregate exercise of system-level privileges
by a plurality of software application instances executing throughout an
enterprise. The forensic device presents a user interface through which
the remote user views the filtered computer evidence acquired from the
target computing device. In this manner, forensic device allows the user
to filter the collected computer evidence to data that is likely to have
forensic relevance.
| Inventors: |
Adelstein; Frank; (Ithaca, NY)
; Marceau; Carla; (Ithaca, NY)
|
| Correspondence Name and Address:
|
SHUMAKER & SIEFFERT, P. A.
1625 RADIO DRIVE, SUITE 300
WOODBURY
MN
55125
US
|
| Assignee Name and Adress: |
Architecture Technology Corporation
|
| Serial No.:
|
469558 |
| Series Code:
|
12
|
| Filed:
|
May 20, 2009 |