First Steps, Lasting Impact: Platform-Aware Forensics for the Next Generation of Analysts
Vinayak Jain, Sneha Sudhakaran, Saranyan Senthivel

TL;DR
This paper systematically evaluates disk and memory forensic techniques across Windows and Linux platforms, identifying effective tool combinations and highlighting persistent gaps in evidence reliability and integrity assurance.
Contribution
It provides a comprehensive assessment of platform-specific forensic methods and proposes tailored configurations to enhance evidence collection accuracy.
Findings
Disk and memory forensics vary significantly between Windows and Linux.
Certain tools are more effective when tailored to specific operating system features.
There are ongoing challenges in ensuring forensic evidence reliability and integrity.
Abstract
The reliability of cyber forensic evidence acquisition is strongly influenced by the underlying operating systems, Windows, macOS, and Linux - due to inherent variations in file system structures, encryption protocols, and forensic tool compatibility. Disk forensics, one of the most widely used techniques in digital investigations, faces distinct obstacles on each platform. Windows, with its predominantly NTFS and FAT file systems, typically supports reliable disk imaging and analysis through established tools such as FTK Imager and Autopsy/Sleuth Kit. However, encryption features frequently pose challenges to evidence acquisition. Conversely, Linux environments, which rely on file systems like ext4 and XFS, generally offer greater transparency, yet the transient nature of log retention often complicates forensic analysis. In instances where anti-forensic strategies such as encryption…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDigital and Cyber Forensics · Advanced Data Storage Technologies · Security and Verification in Computing
