Windows Registry Forensics

Windows Registry Forensics

4.11 - 1251 ratings - Source

Harlan Carvey brings readers an advanced book on Windows Registry. The first book of its kind EVER -- Windows Registry Forensics provides the background of the Registry to help develop an understanding of the binary structure of Registry hive files. Approaches to live response and analysis are included, and tools and techniques for postmortem analysis are discussed at length. Tools and techniques will be presented that take the analyst beyond the current use of viewers and into real analysis of data contained in the Registry. Named a 2011 Best Digital Forensics Book by InfoSec Reviews Packed with real-world examples using freely available open source tools Deep explanation and understanding of the Windows Registry a€“ the most difficult part of Windows to analyze forensically Includes a CD containing code and author-created tools discussed in the bookFor example, on my system, the a€œ.jsa€ extension has a a€œ(Default)a€ value of a€œ UltraEdit.js, a€ indicating the files with this ... on Windows XP, Vista, and Windows 7 , you can check the available Prefetch files to see which browsers may have beenanbsp;...

Title:Windows Registry Forensics
Author:Harlan Carvey
Publisher:Elsevier - 2011-01-03


You Must CONTINUE and create a free account to access unlimited downloads & streaming