Windows Forensic Analysis Toolkit Advanced Analysis Techniques for Windows 7

ISBN-10: 1597497274

ISBN-13: 9781597497275

Edition: 3rd 2012

Authors: Harlan Carvey
List price: $69.95 Buy it from $16.86
eBook available
This item qualifies for FREE shipping

*A minimum purchase of $35 is required. Shipping is provided via FedEx SmartPost® and FedEx Express Saver®. Average delivery time is 1 – 5 business days, but is not guaranteed in that timeframe. Also allow 1 - 2 days for processing. Free shipping is eligible only in the continental United States and excludes Hawaii, Alaska and Puerto Rico. FedEx service marks used by permission."Marketplace" orders are not eligible for free or discounted shipping.

30 day, 100% satisfaction guarantee

If an item you ordered from TextbookRush does not meet your expectations due to an error on our part, simply fill out a return request and then return it by mail within 30 days of ordering it for a full refund of item cost.

Learn more about our returns policy

Description: Author Harlan Carvey has brought his best-selling book up-to-date to give you: the responder, examiner, or analyst the must-have tool kit for your job. Windows is the largest operating system on desktops and servers worldwide, which mean more intrusions, malware infections, and cybercrime happen on these systems. Windows Forensic Analysis DVD Toolkit, 2E covers both live and post-mortem response collection and analysis methodologies, addressing material that is applicable to law enforcement, the federal government, students, and consultants. The book is also accessible to system administrators, who are often the frontline when an incident occurs, but due to staffing and budget constraints do not have the necessary knowledge to respond effectively. The book's companion DVD contains significant new and updated materials (movies, spreadsheet, code, etc.) not available any place else, because they are created and maintained by the author.Best-Selling Windows Digital Forensic book completely updated in this 2nd EditionLearn how to Analyze Data During Live and Post-Mortem InvestigationsDVD Includes Custom Tools, Updated Code, Movies, and Spreadsheets!A brand-new chapter, "Forensic Analysis on a Budget," collects freely available tools that are essential for small labs, state (or below) law enforcement, and educational organizationsNew pedagogical elements, Lessons from the Field, Case Studies, and War Stories, present real-life experiences from the trenches by an expert in the trenches, making the material real and showing the why behind the howThe companion DVD contains new, significant, and unique materials (movies, spreadsheet, code, etc.) not available anyplace else because they were created by the author

New Starting from $80.60
eBooks Starting from $69.95
Buy eBooks
what's this?
Rush Rewards U
Members Receive:
coins
coins
You have reached 400 XP and carrot coins. That is the daily max!

Study Briefs

Limited time offer: Get the first one free! (?)

All the information you need in one place! Each Study Brief is a summary of one specific subject; facts, figures, and explanations to help you learn faster.

Add to cart
Study Briefs
Periodic Table Online content $4.95 $1.99
Add to cart
Study Briefs
SQL Online content $4.95 $1.99
Add to cart
Study Briefs
MS Excel® 2010 Online content $4.95 $1.99
Add to cart
Study Briefs
MS Word® 2010 Online content $4.95 $1.99

Customers also bought

Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading
Loading

Book details

List price: $69.95
Edition: 3rd
Copyright year: 2012
Publisher: Elsevier Science & Technology Books
Publication date: 1/27/2012
Binding: Paperback
Pages: 296
Size: 7.50" wide x 9.25" long x 1.00" tall
Weight: 1.452
Language: English

Harlan Carvey (CISSP) is a Vice President of Advanced Security Projects with Terremark Worldwide, Inc. Terremark is a leading global provider of IT infrastructure and "cloud computing" services, based in Miami, FL. Harlan is a key contributor to the Engagement Services practice, providing disk forensics analysis, consulting, and training services to both internal and external customers. Harlan has provided forensic analysis services for the hospitality industry, financial institutions, as well as federal government and law enforcement agencies. Harlan's primary areas of interest include research and development of novel analysis solutions, with a focus on Windows platforms. Harlan holds a bachelor's degree in electrical engineering from the Virginia Military Institute and a master's degree in the same discipline from the Naval Postgraduate School. Harlan resides in Northern Virginia with his family.

Preface
Acknowledgments
About the Author
About the Technical Editor
Analysis Concepts
Introduction
Analysis Concepts
Windows Versions
Analysis Principles
Documentation
Convergence
Virtualization
Setting Up an Analysis System
Summary
Immediate Response
Introduction
Being Prepared to Respond
Questions
The Importance of Preparation
Logs
Data Collection
Training
Summary
Volume Shadow Copies
Introduction
What Are "Volume Shadow Copies"?
Registry Keys
Live Systems
ProDiscover
F-Response
Acquired Images
VHD Method
VMWare Method
Automating VSC Access
ProDiscover
Summary
Reference
File Analysis
Introduction
MFT
File System Tunneling
Event Logs
Windows Event Log
Recycle Bin
Prefetch Files
Scheduled Tasks
Jump Lists
Hibernation Files
Application Files
Antivirus Logs
Skype
Apple Products
Image Files
Summary
References
Registry Analysis
Introduction
Registry Analysis
Registry Nomenclature
The Registry as a Log File
USB Device Analysis
System Hive
Software Hive
User Hives
Additional Sources
Tools
Summary
References
MaIware Detection
Introduction
Malware Characteristics
Initial Infection Vector
Propagation Mechanism
Persistence Mechanism
Artifacts
Detecting Malware
Log Analysis
Antivirus Scans
Digging Deeper
Seeded Sites
Summary
References
Timeline Analysis
Introduction
Timelines
Data Sources
Time Formats
Concepts
Benefits
Format
Creating Timelines
File System Metadata
Event Logs
Prefetch Files
Registry Data
Additional Sources
Parsing Events into a Timeline
Thoughts on Visualization
Case Study
Summary
Application Analysis
Introduction
Log Files
Dynamic Analysis
Network Captures
Application Memory Analysis
Summary
References
Index
×
Free shipping on orders over $35*

*A minimum purchase of $35 is required. Shipping is provided via FedEx SmartPost® and FedEx Express Saver®. Average delivery time is 1 – 5 business days, but is not guaranteed in that timeframe. Also allow 1 - 2 days for processing. Free shipping is eligible only in the continental United States and excludes Hawaii, Alaska and Puerto Rico. FedEx service marks used by permission."Marketplace" orders are not eligible for free or discounted shipping.

Learn more about the TextbookRush Marketplace.

×