000 02606nam a2200241Ia 4500
003 NULRC
005 20250520100607.0
008 250520s9999 xx 000 0 und d
020 _a9781597497275
040 _cNULRC
050 _aHV 8079.C65 .C37 2012
100 _aCarvey, Harlan A.
_eauthor
245 0 _aWindows forensic analysis toolkit :
_badvanced analysis techniques for Windows 7 /
_cHarlan Carvey
250 _aThird edition.
260 _aRockland, Massachusetts :
_bSyngress,
_cc2012
300 _axxi, 296 pages :
_billustrations ;
_c24 cm.
365 _bUSD57.05
504 _aIncludes bibliographical references.
505 _aChapter 1 Analysis Concepts -- Chapter 2 Immediate response -- Chapter 3 Volume shadow copies -- Chapter 4 File analysis -- Chapter 5 Registry analysis -- Chapter 6 Malware detection -- Chapter 7 Timeline analysis -- Chapter 8 Application analysis.
520 _aWindows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and postmortem response collection and analysis methodologies for Windows 7. It considers the core investigative and analysis concepts that are critical to the work of professionals within the digital forensic analysis community, as well as the need for immediate response once an incident has been identified. Organized into eight chapters, the book discusses Volume Shadow Copies (VSCs) in the context of digital forensics and explains how analysts can access the wealth of information available in VSCs without interacting with the live system or purchasing expensive solutions. It also describes files and data structures that are new to Windows 7 (or Vista), Windows Registry Forensics, how the presence of malware within an image acquired from a Windows system can be detected, the idea of timeline analysis as applied to digital forensic analysis, and concepts and techniques that are often associated with dynamic malware analysis. Also included are several tools written in the Perl scripting language, accompanied by Windows executables. This book will prove useful to digital forensic analysts, incident responders, law enforcement officers, students, researchers, system administrators, hobbyists, or anyone with an interest in digital forensic analysis of Windows 7 systems. Timely 3e of a Syngress digital forensic bestseller Updated to cover Windows 7 systems, the newest Windows version New online companion website houses checklists, cheat sheets, free tools, and demos.
650 _aCOMPUTER CRIMES -- INVESTIGATION -- UNITED STATES -- METHODOLOGY
942 _2lcc
_cBK
999 _c8962
_d8962