ShadowCopyView is a simple tool developed by NirSoft (remember this name! They have developed lots of small free tools which are extremely useful for computer forensics), which enables digital forensic examiners to browse snapshots created by the Windows Volume Shadow Copy Service. It supports even the most recent Windows versions (Windows 10, for example), and can be kept on your favorite USB drive, which is very important for live forensics and incident response.
Browsing and copying files from VSCs on a live system with ShadowCopyView
Getting ready
Go to NirSoft's website and click on the All Utilities link on the left. Scroll down the page, find the ShadowCopyView link, and click it. At the time of writing, the most...