官术网_书友最值得收藏!

What this book covers

Chapter 1, Digital Forensics and Evidence Acquisition, will give you a brief overview of digital forensics as a science, and will cover the basics of digital evidence acquisition, examination and reporting.

Chapter 2, Windows Memory Acquisition and Analysis, will guide you through Windows memory acquisition with Belkasoft RAM Capturer and DumpIt. After you will learn how to analyze memory images with Belkasoft Evidence Center and Volatility.

Chapter3, Windows Drive Acquisition, will guide you through the acquisition of the main source of Windows forensic artifacts hard and solid state drives. You will learn how to create forensic images with FTK Imager and DC3DD, and also how to mount them with Arsenal Image Mounter.

Chapter4, Windows File Systems Analysis, will guide you through the analysis of the most common Windows filesystem, New Technology File System or NTFS, with the Sleuth Kit. Also, you will learn how to recover deleted files from both NTFS and its descendant, ReFS, using Autopsy, ReclaiMe Pro, and PhotoRec.

Chapter5, Windows Shadow Copies Analysis, will show you how to browse and copy files from VSCs with ShadowCopyView. Also you will learn how to mount these copies with VSSADMIN and MKLINK, and analyze their data with Magnet AXIOM.

Chapter6, Windows Registry Analysis, will show you how to extract data from the Windows Registry with Magnet AXIOM and the RegRipper. Also, you will learn how to recover deleted Registry artifacts with the Registry Explorer.

Chapter 7, Main Windows Operating System Artifacts, will introduce you to the main Windows forensic artifacts, including the Recycle Bin items, Windows Event Logs, LNK files, and Prefetch files. You will learn how to analyze these artifacts with EnCase Forensic, Rifiuti2, Magnet AXIOM, FullEventLogView, EVTXtract, LECmd, Link Parser, PECmd, and Windows Prefetch Carver.

Chapter 8, Web Browser Forensics, will guide you through the analysis of the most popular Windows web browser with BlackBagBlackLight, Magnet Axiom, and Belkasoft Evidence Center. Also, you will learn how to extract browser data from a paging file.

Chapter 9, Email and Instant Messaging Forensics, will show you how to analyze artifacts of the most popular Windows email clients Microsoft Outlook and Mozilla Thunderbird, and the instant messaging application Skype. Also, you will learn how to extract webmail artifacts from a forensic image.

Chapter 10, Windows 10 Forensics, will introduce you to Windows 10—specific artifacts, such as Cortana, the Mail app, Xbox app, and notifications. You will learn where the data is stored, its format, and how to extract and analyze it.

Chapter 11, Data Visualization, will show you how to make your forensic reports even better with data visualization techniques. You will learn how to use these techniques in Forensic Toolkit (FTK), Autopsy, and Nuix.

Chapter 12, Troubleshooting in Windows Forensic Analysis, will teach you how to solve problems with your forensic software, both commercial and free/open source; show you what to do if processes fail, why its important to analyze false positives, give you recommendations on your first steps in digital forensics; and provide a nice list of sources for further reading.

主站蜘蛛池模板: 萝北县| 临潭县| 菏泽市| 伊吾县| 大同县| 汾西县| 历史| 岗巴县| 灵山县| 蓬莱市| 黄平县| 孟津县| 天峻县| 中方县| 怀仁县| 甘肃省| 武夷山市| 峨山| 石嘴山市| 凤城市| 梧州市| 葵青区| 汉源县| 塘沽区| 化德县| 天长市| 老河口市| 加查县| 太保市| 腾冲县| 宜川县| 塔城市| 裕民县| 沐川县| 林西县| 琼中| 车致| 高碑店市| 诸暨市| 遵化市| 夹江县|