January 2020
Intermediate to advanced
448 pages
11h 42m
English
When investigating an incident, it is critical to have an idea of when applications or files were executed. Timestamps can sometimes be found in other aspects of the investigation, such as when examining memory images. Also, identifying specific DLL files or executable files in the memory image can be compared to the date and time they were accessed in order to correlate other activity that's been observed on the system.
Read now
Unlock full access