Freshly Printed - allow 10 days lead
Windows Registry Forensics
Advanced Digital Forensic Analysis of the Windows Registry
The second edition of this go-to reference provides readers with the information, tools, and processes needed to find and analyze forensic evidence using Windows Registry. Tools and techniques for post mortem analysis are discussed at length to take users beyond the current use of viewers and into real analysis of data contained in the Registry
Harlan Carvey (Author)
9780128032916, Elsevier Science
Paperback, published 31 March 2016
216 pages, 31 illustrations (16 in full color)
23.5 x 19 x 1.5 cm, 0.48 kg
Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition, provides the most in-depth guide to forensic investigations involving Windows Registry. This book is one-of-a-kind, giving the background of the Registry to help users develop an understanding of the structure of registry hive files, as well as information stored within keys and values that can have a significant impact on forensic investigations. Tools and techniques for post mortem analysis are discussed at length to take users beyond the current use of viewers and into real analysis of data contained in the Registry. This second edition continues a ground-up approach to understanding so that the treasure trove of the Registry can be mined on a regular and continuing basis.
1. Registry Analysis 2. Processes and Tools 3. Case Studies: The System 4. Case Studies: Tracking User Activity 5. RegRipper
Subject Areas: Computer security [UR], Operating systems [UL], Forensic science [JKVF1]