Date: February 2014


Google Drive Forensics

by Destruct_Icon
Categories: Analysis, Host Forensics
Tags: No Tags
Comments: Leave a Comment

Google Drive Forensics Google Drive has some very useful artifacts that help identify not only what a user may have pushed to the cloud, but also what they have pulled and stored on the current system.  The three main files we will be looking at are: System Drive/Users/(Username)/AppData/Local/Google/Drive/snapshot.db System Drive/Users/(Username)/AppData/Local/Google/Drive/sync_config.db System Drive/Users/(Username)/AppData/Local/Google/Drive/sync_log.txt These three files[…]

Today is Friday