Windows Forensic Analysis Toolkit
Advanced Analysis Techniques for Windows 7
- 3rd Edition - January 27, 2012
- Author: Harlan Carvey
- Language: English
Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and postmortem response collection and analysis methodologies for Windows… Read more
- Timely 3e of a Syngress digital forensic bestseller
- Updated to cover Windows 7 systems, the newest Windows version
- New online companion website houses checklists, cheat sheets, free tools, and demos
Computer forensic and incident response professionals. This includes LE, federal government, commercial/private sector contractors, consultants, etc.
- Dedication
- Preface
- Acknowledgments
- About the Author
- About the Technical Editor
- Chapter 1. Analysis Concepts
- Introduction
- Analysis Concepts
- Setting up an Analysis System
- Summary
- Chapter 2. Immediate Response
- Introduction
- Being Prepared to Respond
- Data Collection
- Summary
- Chapter 3. Volume Shadow Copies
- Introduction
- What are “Volume Shadow Copies”?
- Live Systems
- Acquired Images
- Summary
- Chapter 4. File Analysis
- Introduction
- MFT
- Event Logs
- Recycle Bin
- Prefetch Files
- Scheduled Tasks
- Jump Lists
- Hibernation Files
- Application Files
- Summary
- Chapter 5. Registry Analysis
- Introduction
- Registry Analysis
- Summary
- Chapter 6. Malware Detection
- Introduction
- Malware Characteristics
- Detecting Malware
- Summary
- Chapter 7. Timeline Analysis
- Introduction
- Timelines
- Creating Timelines
- Case Study
- Summary
- Chapter 8. Application Analysis
- Introduction
- Log Files
- Dynamic Analysis
- Network Captures
- Application Memory Analysis
- Summary
- Index
"Harlan has done it again! Continuing in the tradition of excellence established by the previous editions, Windows Forensics Analysis Toolkit 3e is an indispensable resource for any forensic examiner. Whether you're a seasoned veteran or just starting out, this work is required reading. WFA3e will maintain a perennial spot on my core reference bookshelf!"—Cory Altheide, Google
"Windows Forensic Analysis Toolkit 3rd Edition provides a wealth of important information for new and old practitioners alike. Not only does it provide a great overview of artifacts of interest on Windows 7 systems, but it also presents plenty of technology independent concepts that play an important role in any investigation. Feel free to place a copy on your shelf next to WFA 2ed and WRF."—Digital4rensics.com
"The third edition of this reference for system administrators, digital forensic analysts, students, and law enforcement does not replace the second edition, but rather serves as a companion. Coverage encompasses areas such as immediate response, volume shadow copies, file and registry analysis, malware detection, and application analysis. Learning features include b&w screenshots, tip and warning boxes, code (also available on a website), case studies, and 'war stories' from the field. The tools described throughout the book are written in the Perl scripting language, but readers don't need to be experts in Perl, and most of the scripts are accompanied by Windows executables found online. For this third edition, a companion website provides printable checklists, cheat sheets, custom tools, and demos."—Reference and Research Book News, Inc.
"There is a good reason behind the success of the previous editions of this book, and it has to do with two things: new Windows versions are different enough from previous ones to warrant a new edition and, most importantly, the author is simply that good at explaining things. This edition is no different."—HelpNetSecurity
- Edition: 3
- Published: January 27, 2012
- Language: English
HC