today I want to share this interesting paper on Facebook Forensics. Actually most of the paper it's a simple way to find out if in the analyzed machine there is at least a FB account. So it's nothing really exceptional at all, just memory and Hard Drive forensic, but it offers a great list of the used toolset and a nice presentation style with a lot of screen captures and examples.
While the first part could be obvious for most of you, the second part talks about Virtual Machine forensics. Again, it's not a specific paper on such a topic. Much more "deep" papers could be easily found on IEEExplorer or ACM or even in Google scholar (here, here, here, here, here and here) but it is a well written part, perfect for whom is seeking an easy and understandable example made from scratch. Have a nice reading !