Tuesday, February 19, 2019

Daily Blog #627: Deep Freeze and DFIR

            While I didn't have any winners for last week's Sunday Funday I did want to draw your attention to the answers that were already present, from 8 years ago. Lance Mueller who wrote/writes the ForensicKB blog did his own Deep Freeze testing 8 years ago. Jessica Hyde reminded me of this while I was doing my own testing and it appears that Lance went even farther than I did in my first couple of tests.

So if you were looking for the answers to how Deep Freeze is writing data and discarding it between reboots I would suggest brushing up on Lance's research below:


