- Добавил: literator
- Дата: 29-05-2024, 19:37
- Комментариев: 0
Название: Windows Forensics: Understand Analysis Techniques for Your Windows
Автор: Chuck Easttom, William Butler, Jessica Phelan, Ramya Sai Bhagavatula
Издательство: Apress
Год: 2024
Страниц: 484
Язык: английский
Формат: pdf
Размер: 26.4 MB
This book is your comprehensive guide to Windows forensics. It covers the process of conducting or performing a forensic investigation of systems that run on Windows operating systems. It also includes analysis of incident response, recovery, and auditing of equipment used in executing any criminal activity. The book covers Windows registry, architecture, and systems as well as forensic techniques, along with coverage of how to write reports, legal standards, and how to testify. It starts with an introduction to Windows followed by forensic concepts and methods of creating forensic images. You will learn Windows file artefacts along with Windows Registry and Windows Memory forensics. And you will learn to work with PowerShell scripting for forensic applications and Windows email forensics. Microsoft Azure and cloud forensics are discussed and you will learn how to extract from the cloud. By the end of the book you will know data-hiding techniques in Windows and learn about volatility and a Windows Registry cheat sheet. This book is designed for two audiences. The first is the student that is learning forensics. This could be in a university setting or less formal setting. As the book assumes no prior knowledge of either forensics or Microsoft Windows, it can be used by a beginner. The second audience is the professional forensic examiner that requires a more in-depth understanding of Microsoft Windows forensics. This book will provide a depth that will give you a thorough understanding of how to do Windows forensics.
Автор: Chuck Easttom, William Butler, Jessica Phelan, Ramya Sai Bhagavatula
Издательство: Apress
Год: 2024
Страниц: 484
Язык: английский
Формат: pdf
Размер: 26.4 MB
This book is your comprehensive guide to Windows forensics. It covers the process of conducting or performing a forensic investigation of systems that run on Windows operating systems. It also includes analysis of incident response, recovery, and auditing of equipment used in executing any criminal activity. The book covers Windows registry, architecture, and systems as well as forensic techniques, along with coverage of how to write reports, legal standards, and how to testify. It starts with an introduction to Windows followed by forensic concepts and methods of creating forensic images. You will learn Windows file artefacts along with Windows Registry and Windows Memory forensics. And you will learn to work with PowerShell scripting for forensic applications and Windows email forensics. Microsoft Azure and cloud forensics are discussed and you will learn how to extract from the cloud. By the end of the book you will know data-hiding techniques in Windows and learn about volatility and a Windows Registry cheat sheet. This book is designed for two audiences. The first is the student that is learning forensics. This could be in a university setting or less formal setting. As the book assumes no prior knowledge of either forensics or Microsoft Windows, it can be used by a beginner. The second audience is the professional forensic examiner that requires a more in-depth understanding of Microsoft Windows forensics. This book will provide a depth that will give you a thorough understanding of how to do Windows forensics.