O'Reilly logo

Windows Forensic Analysis DVD Toolkit, 2nd Edition by Harlan Carvey

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Chapter 5. File Analysis

Solutions in this chapter

▪ Log Files
▪ File Metadata
▪ Alternative Methods of Analysis
Summary
Solutions Fast Track
Frequently Asked Questions

Introduction

Windows systems maintain quite a number of files that are useful from a forensic perspective. In fact, many investigators might not realize the wealth of data they can find within some of the files that Windows systems use to track various activity and functions. Knowing multiple locations where information is maintained within the system allows an investigator to corroborate information that is found in other areas and reduce the amount of uncertainty in their analysis. In this chapter, we'll discuss some of the various files, including log files, you can find on Windows ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required