February 2026
Intermediate to advanced
456 pages
17h 3m
English
This chapter introduced you to the details of forensic analysis of a Microsoft Windows system. You should pay particular attention to the Registry and the forensic data you can extract from it. Also important to your forensic investigation is the index.dat file. These two are the most important items to learn in this chapter.
Additional topics in this chapter, such as examining the swap file and extracting data from a live system, are also important to any forensic examination of a Windows computer. But they may not yield quite as much information as examining index.dat and the Registry.
Read now
Unlock full access