Quiz 9 Question 6 of 20

During a forensic investigation on a Windows system, an analyst discovers that the attacker ran commands that left no files on disk. Which forensic technique can recover evidence of these commands?

Select an answer to reveal the explanation.

Motivation