Skip to content

Forensic Examination of Windows-Supported File Systems

Best in textbook rentals since 2012!

ISBN-10: 1497358353

ISBN-13: 9781497358355

Edition: N/A

Authors: Doug Elrick, Drew Elrick, Lane Pelovsky, Lauren Bernhagen, Keith Lockhart

List price: $114.99
Shipping box This item qualifies for FREE shipping.
Blue ribbon 30 day, 100% satisfaction guarantee!
what's this?
Rush Rewards U
Members Receive:
Carrot Coin icon
XP icon
You have reached 400 XP and carrot coins. That is the daily max!

Description:

Understanding the underlying system of how files are stored, what happens when they are deleted, and how to potentially recover them is essential to the forensic examiner. Today's tools automate the process of file recovery, but understanding what those tools are accomplishing and knowing whether they are providing accurate results requires an understanding of the information provided in this text. The FAT and NTFS file systems are the most commonly utilized information storage methods and while there are many other methods available, concentrating on these two lays the foundation for learning the others in the future. A brief introduction of ExFAT is included, as it is a relatively new…    
Customers also bought

Book details

List price: $114.99
Publisher: CreateSpace Independent Publishing Platform
Publication date: 4/7/2014
Binding: Paperback
Pages: 392
Size: 8.50" wide x 11.00" long x 1.00" tall
Weight: 2.684
Language: English

Doug Elrick has worked in the area of digital forensics for over twenty years. He instructs law enforcement and corporate security investigators in proper forensic methodologies and in the use of common computer forensic applications. Doug holds a Master's of Science in Digital Forensics from the University of Central Florida and has obtained the following digital forensic certifications: CFCE and CAWFE from IACIS, EnCE from Guidance Software, and ACE from AccessData.

Malcolm Bull teaches at Oxford University.Keith Lockhart is a London-based journalist