{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,27]],"date-time":"2025-12-27T03:21:12Z","timestamp":1766805672735,"version":"3.41.0"},"reference-count":12,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2006,2,1]],"date-time":"2006-02-01T00:00:00Z","timestamp":1138752000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2006,2]]},"abstract":"<jats:p>Live analysis tools have made a significant difference in capturing evidence during forensic investigations. Such tools, however, are far from infallible.<\/jats:p>","DOI":"10.1145\/1113034.1113069","type":"journal-article","created":{"date-parts":[[2006,2,6]],"date-time":"2006-02-06T15:07:09Z","timestamp":1139238429000},"page":"56-61","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":45,"title":["Risks of live digital forensic analysis"],"prefix":"10.1145","volume":"49","author":[{"given":"Brian D.","family":"Carrier","sequence":"first","affiliation":[]}],"member":"320","published-online":{"date-parts":[[2006,2]]},"reference":[{"volume-title":"Addison Wesley","year":"2005","author":"Carrier B.D.","key":"e_1_2_1_1_1"},{"key":"e_1_2_1_2_1","unstructured":"Carrier B.D. The Sleuth Kit; www.sleuthkit.org\/.  Carrier B.D. The Sleuth Kit; www.sleuthkit.org\/."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2003.12.001"},{"key":"e_1_2_1_4_1","unstructured":"Cogswell B. and Russinovich M. RootkitRevealer; www.sysinternals.com.  Cogswell B. and Russinovich M. RootkitRevealer; www.sysinternals.com."},{"key":"e_1_2_1_5_1","unstructured":"Guidance Software. EnCase Enterprise; www.encase.com.  Guidance Software. EnCase Enterprise; www.encase.com."},{"volume-title":"Addison Wesley","year":"2005","author":"Hoglund G.","key":"e_1_2_1_6_1"},{"volume-title":"McGraw-Hill","year":"2003","author":"Mandia K.","key":"e_1_2_1_7_1"},{"volume-title":"Proceedings of 13th Annual USENIX Security Symposium (Aug.","year":"2004","author":"Petroni Jr., N.L.","key":"e_1_2_1_8_1"},{"volume-title":"Prentice Hall","year":"2004","author":"Skoudis E.","key":"e_1_2_1_9_1"},{"key":"e_1_2_1_10_1","unstructured":"Technology Pathways. ProDiscover Incident Response; www.techpathways.com\/.  Technology Pathways. ProDiscover Incident Response; www.techpathways.com\/."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/358198.358210"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2005.39"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1113034.1113069","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1113034.1113069","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:08:25Z","timestamp":1750262905000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1113034.1113069"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,2]]},"references-count":12,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2006,2]]}},"alternative-id":["10.1145\/1113034.1113069"],"URL":"https:\/\/doi.org\/10.1145\/1113034.1113069","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"type":"print","value":"0001-0782"},{"type":"electronic","value":"1557-7317"}],"subject":[],"published":{"date-parts":[[2006,2]]},"assertion":[{"value":"2006-02-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}