Book description
Windows Registry Forensics provides the background of the Windows Registry to help develop an understanding of the binary structure of Registry hive files. Approaches to live response and analysis are included, and tools and techniques for postmortem analysis are discussed at length. Tools and techniques are presented that take the student and analyst beyond the current use of viewers and into real analysis of data contained in the Registry, demonstrating the forensic value of the Registry.
Named a 2011 Best Digital Forensics Book by InfoSec Reviews, this book is packed with real-world examples using freely available open source tools. It also includes case studies and a CD containing code and author-created tools discussed in the book.
This book will appeal to computer forensic and incident response professionals, including federal government and commercial/private sector contractors, consultants, etc.
- Named a 2011 Best Digital Forensics Book by InfoSec Reviews
- Packed with real-world examples using freely available open source tools
- Deep explanation and understanding of the Windows Registry – the most difficult part of Windows to analyze forensically
- Includes a CD containing code and author-created tools discussed in the book
Product information
- Title: Windows Registry Forensics
- Author(s):
- Release date: January 2011
- Publisher(s): Syngress
- ISBN: 9781597495813
You might also like
book
Windows Registry Troubleshooting
Whatever version of Windows you’re using--from Vista up to Windows 8.1--the registry is at the heart …
book
Malware Forensics
Malware Forensics: Investigating and Analyzing Malicious Code covers the complete process of responding to a malicious …
book
Windows Forensic Analysis DVD Toolkit, 2nd Edition
Windows Forensic Analysis DVD Toolkit, Second Edition, is a completely updated and expanded version of Harlan …
book
Computer Forensics and Digital Investigation with EnCase Forensic v7
Conduct repeatable, defensible investigations with EnCase Forensic v7 Maximize the powerful tools and features of the …