Skip to Main Content
Practical Memory Forensics
book

Practical Memory Forensics

by Svetlana Ostrovskaya, Oleg Skulkin
March 2022
Intermediate to advanced content levelIntermediate to advanced
304 pages
5h 58m
English
Packt Publishing
Content preview from Practical Memory Forensics

Chapter 4: Reconstructing User Activity with Windows Memory Forensics

User activity reconstruction is essential for many use cases since it gives us a better understanding of what is going on. In the first chapter, we discussed that if you receive a device participating in the incident, the victim or suspect probably owned this device. If we analyze the victim's device, user activity can tell us how the infection occurred or how the attacker acted while remotely accessing the computer. If we are talking about the attacker's device, such analysis allows us to understand how the preparation for the attack took place, what actions the threat actor performed, and how to find evidence of illegitimate activity. Also, if you are dealing with criminal ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Windows Forensics

Practical Windows Forensics

Ayman Shaaban, Konstantin Sapronov
Practical Mobile Forensics - Fourth Edition

Practical Mobile Forensics - Fourth Edition

Rohit Tamma, Oleg Skulkin, Heather Mahalik, Satish Bommisetty
Learn Computer Forensics

Learn Computer Forensics

William Oettinger

Publisher Resources

ISBN: 9781801070331