Hackviser Training
Volume Shadow Copy Services (VSS) Analysis
7 sections3 tools
Training Overview
The "Volume Shadow Copy Services (VSS) Analysis" training explains how VSS works and how it can be used for data recovery, digital forensics, and security measures. The training begins with the fundamentals of VSS and then delves into its role in digital forensics (DFIR) processes, detailing how to recover data from VSS backups.
What you will learn
- The role of Volume Shadow Copies in digital forensics.
- How to enable and list available shadow copies on a system.
- How to mount a shadow copy for analysis.
- How to recover previous versions of files or deleted data from shadow copies.
Tools you will use
- vssadmin command
- VSCMount
- ShadowCopyView
Prerequisites
- A solid understanding of the Windows file system (NTFS).
- Experience with basic forensic analysis concepts.
Who this is for
- Digital Forensic Investigators.
- Incident Responders.
- System administrators involved in data recovery.
Training sections
- 1Introduction
- 2VSS Analysis in Forensics
- 3Enabling VSS
- 4VSS Analysis
- 5VSCMount
- 6Koruma ve Önleme Yöntemleri
- 7Exam
Continue learning
Practice the topic in a lab or continue with a related Hackviser guide.