LIMITED OFFER
Save 50% on book bundles
Immediately download your ebook while waiting for your print delivery. No promo code needed.
Windows Registry Forensics provides the background of the Windows Registry to help develop an understanding of the binary structure of Registry hive files. Approaches to live resp… Read more
LIMITED OFFER
Immediately download your ebook while waiting for your print delivery. No promo code needed.
Windows Registry Forensics provides the background of the Windows Registry to help develop an understanding of the binary structure of Registry hive files. Approaches to live response and analysis are included, and tools and techniques for postmortem analysis are discussed at length. Tools and techniques are presented that take the student and analyst beyond the current use of viewers and into real analysis of data contained in the Registry, demonstrating the forensic value of the Registry.
Named a 2011 Best Digital Forensics Book by InfoSec Reviews, this book is packed with real-world examples using freely available open source tools. It also includes case studies and a CD containing code and author-created tools discussed in the book.
This book will appeal to computer forensic and incident response professionals, including federal government and commercial/private sector contractors, consultants, etc.
Chapter 1 Registry Analysis
Introduction
What is "Registry Analysis"?
What is the Windows Registry?
Registry Structure
Summary
Frequently Asked Questions
References
Chapter 2 Tools
Introduction
Live Analysis
Summary
Frequently Asked Questions
References
Chapter 3 Case Studies: The System
Introduction
Security and SAM hives
System Hive
Software Hive
BCD Hive
Summary
Frequently Asked Questions
References
Chapter 4 Case Studies: Tracking User Activity
Introduction
Tracking User Activity
Scenarios
Summary
References
HC