Book description
Harlan Carvey has updated Windows Forensic Analysis Toolkit, now in its fourth edition, to cover Windows 8 systems. The primary focus of this edition is on analyzing Windows 8 systems and processes using free and open-source tools. The book covers live response, file analysis, malware detection, timeline, and much more. Harlan Carvey presents real-life experiences from the trenches, making the material realistic and showing the why behind the how.
The companion and toolkit materials are hosted online. This material consists of electronic printable checklists, cheat sheets, free custom tools, and walk-through demos. This edition complements Windows Forensic Analysis Toolkit, Second Edition, which focuses primarily on XP, and Windows Forensic Analysis Toolkit, Third Edition, which focuses primarily on Windows 7.
This new fourth edition provides expanded coverage of many topics beyond Windows 8 as well, including new cradle-to-grave case examples, USB device analysis, hacking and intrusion cases, and "how would I do this" from Harlan's personal case files and questions he has received from readers. The fourth edition also includes an all-new chapter on reporting.
- Complete coverage and examples of Windows 8 systems
- Contains lessons from the field, case studies, and war stories
- Companion online toolkit material, including electronic printable checklists, cheat sheets, custom tools, and walk-throughs
Table of contents
- Cover image
- Title page
- Copyright
- Dedication
- Preface
- Acknowledgments
- About the Author
- About the Technical Editor
- Chapter 1. Analysis Concepts
- Chapter 2. Incident Preparation
- Chapter 3. Volume Shadow Copies
- Chapter 4. File Analysis
- Chapter 5. Registry Analysis
- Chapter 6. Malware Detection
- Chapter 7. Timeline Analysis
- Chapter 8. Correlating Artifacts
- Chapter 9. Reporting
- Index
Product information
- Title: Windows Forensic Analysis Toolkit, 4th Edition
- Author(s):
- Release date: March 2014
- Publisher(s): Syngress
- ISBN: 9780124171749
You might also like
book
Windows Forensic Analysis Toolkit, 3rd Edition
Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and …
book
Windows Registry Forensics, 2nd Edition
Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition, provides the most …
book
The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory
Memory forensics provides cutting edge technology to help investigate digital attacks Memory forensics is the art …
book
Mastering Windows Network Forensics and Investigation, 2nd Edition
An authoritative guide to investigating high-technology crimes Internet crime is seemingly ever on the rise, making …