Chapter 5. Windows Forensic Analysis
Ryan D. Pittman and Dave Shaver
Contents
Windows, Windows Everywhere
210 Forensic Analysis of the NTFS Master File Table (MFT)
223 Artifacts of User Activities
235 Deletion and Destruction of Data
273 Windows Internet and Communications Activities
279 Windows Process Memory
285 BitLocker and Encrypting File System (EFS)
287 RAIDs and Dynamic Disks
292Introduction
Despite the proliferation and growing popularity of other user interfaces, such as Macintosh OS X and Ubuntu (a flavor of Linux), Microsoft's Windows operating systems remain the most popular in the world. In fact, sources have reported that over 90% of the computers in use today are running ...