Chapter 5. File Analysis

Solutions in this chapter

▪ Log Files
▪ File Metadata
▪ Alternative Methods of Analysis
Summary
Solutions Fast Track
Frequently Asked Questions

Introduction

Windows systems maintain quite a number of files that are useful from a forensic perspective. In fact, many investigators might not realize the wealth of data they can find within some of the files that Windows systems use to track various activity and functions. Knowing multiple locations where information is maintained within the system allows an investigator to corroborate information that is found in other areas and reduce the amount of uncertainty in their analysis. In this chapter, we'll discuss some of the various files, including log files, you can find on Windows ...

Get Windows Forensic Analysis DVD Toolkit, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.