Windows registry forensics advanced digital forensic analysis of the Windows registry Second Edition by Harlan Carvey – Ebook PDF Instant Download/Delivery: 0128033355, 9780128032916
Full download Windows registry forensics advanced digital forensic analysis of the Windows registry Second Edition after payment
Product details:
ISBN 10: 0128033355
ISBN 13: 9780128032916
Author: Harlan Carvey
Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition, provides the most in-depth guide to forensic investigations involving Windows Registry. This book is one-of-a-kind, giving the background of the Registry to help users develop an understanding of the structure of registry hive files, as well as information stored within keys and values that can have a significant impact on forensic investigations. Tools and techniques for post mortem analysis are discussed at length to take users beyond the current use of viewers and into real analysis of data contained in the Registry. This second edition continues a ground-up approach to understanding so that the treasure trove of the Registry can be mined on a regular and continuing basis.
Windows registry forensics advanced digital forensic analysis of the Windows registry Second Table of contents:
1. Registry Analysis
Introduction
Core Analysis Concepts
What Is the Windows Registry?
Registry Structure
Summary
2. Processes and Tools
Introduction
Forensic Analysis
Summary
3. Analyzing the System Hives
Introduction
Artifact Categories
Security Hive
SAM Hive
System Hive
Software Hive
AmCache Hive
Summary
4. Case Studies: User Hives
Introduction
NTUSER.DAT
USRCLASS.DAT
Summary
5. RegRipper
Introduction
What Is RegRipper?
Getting the Most Out of RegRipper
Summary
Index
People also search for Windows registry forensics advanced digital forensic analysis of the Windows registry Second:
windows registry digital forensics
windows registry forensics
windows registry forensics cheat sheet
windows registry artifacts
Tags:
Harlan Carvey,Windows registry,forensics advanced