Question: What traces/evidences (e.g., additional files, modified files, log files, and so on.) may be left behind after a system was attacked by Duqu? Describe these
What traces/evidences (e.g., additional files, modified files, log files, and so on.) may be left behind after a system was attacked by Duqu? Describe these traces in details.
What are they? (traces/evidences left behind)
Where are they? (in/at which places/locations/folders of the victims/infected computers)
How to identify them? (with what tools)
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
