Abstract | Most of digital investigation research on Windows application covers stages of investigation that covers key aspect of forensic image collection, preservation, dumped data and extraction, searching for evidence and possible reconstructions of user input evidence and analysis in a use case environment of business organisations. The user activities on some of the business applications can reveal user involvement on the perception of cyber-human factor. Tangible user information were extracted and reconstructed to determine the forensic artifact in Windows business application. On investigations, the forensic validation process of key stages of digital investigation revealed relevant information on various experiments carried out. The research idea focus on the use cases of MS PowerPoint and MS Excel of Windows business applications. The research determined and formulated the extraction process of user evidence from a sample memory forensics investigation. The quantitative assessment of relevant information was presented to uncovers how user input information are stored and as recovered from the application memory. In this paper, a design methodology to capture, extract and process relevant user information was described on the two most commonly used applications on Windows systems. |
---|