Invention Grant
- Patent Title: Hypervisor-hosted virtual machine forensics
-
Application No.: US15814940Application Date: 2017-11-16
-
Publication No.: US10169071B2Publication Date: 2019-01-01
- Inventor: Jerry Cochran
- Applicant: MICROSOFT TECHNOLOGY LICENSING, LLC
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Agency: Kelly, Holt & Christenson, PLLC
- Agent Christopher J. Volkmann
- Main IPC: G06F9/455
- IPC: G06F9/455 ; G06F9/50

Abstract:
A computer system acquires forensics data from running virtual machines in a hypervisor-hosted virtualization environment. The computer system provides a forensics partition as an additional root virtual machine partition or child virtual machine partition. The forensics partition includes a forensics service application programming interface configured to target one or more virtual machines and acquire forensics data from a targeted virtual machine running in a particular child virtual machine partition. The forensics service application programming interface is configured to communicate via one or more inter-partition communication mechanisms such as an inter-partition communication bus, a hypercall interface, or forensics switch implemented by the hypervisor-hosted virtualization environment. The forensics service application programming interface can be exposed to a forensics tool as part of a cloud-based forensics service.
Public/Granted literature
- US20180088980A1 HYPERVISOR-HOSTED VIRTUAL MACHINE FORENSICS Public/Granted day:2018-03-29
Information query