Talk With an Expert

Quick and Effective Windows System Baselining and Comparative Analysis for Troubleshooting and Incident Response

Quick and Effective Windows System Baselining and Comparative Analysis for Troubleshooting and Incident Response (PDF, 9.19MB)Published: 14 Feb, 2012
Created by:
Kevin Fuller

Baselining is an important tool for troubleshooting, audit, incident response and forensics. It involves documenting the features of a known good state of a system. This can be used to do a comparative analysis of the current system state to determine what has changed and how it was changed. In practice, doing a complete and documented system baseline can be time consuming and cumbersome and is infrequently done. The goal of this paper is to highlight a pair of tools and a methodology that can provide the ability to baseline a Windows system in a more complete manner across a number of areas. More importantly, the methodology will demonstrate the ability to do a quick, effective comparative analysis of a baseline and the current state to determine what has changed.