Variations in Windows versions
As you already know from the first chapter, nowadays we have a number of different Windows versions widely used both by private persons and businesses. Of course, this has an impact on Windows operating system forensic examinations, including Windows memory forensics.
Getting ready
Knowing the Windows version and its type is very important, both in the acquisition and analysis stages. There are a few ways to collect this information. We will cover some in this recipe.
How to do it...
The easiest way to find out which version a computer is running is by following these steps:
- Click on
Start
. - Go to
Run
. - Type
winver
in the search field and press Enter.
This will work on machines that have installed Windows 7 or earlier versions. For Windows 8 onwards:
- You will need to press and hold the Windows key along with R
- Type
winver
in the box that appears and press Enter
This will open a small About Windows
box, which will provide information on the version, as well as the build...