Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and postmortem response collection and analysis methodologies for Windows 7. It considers the core investigative and analysis concepts that are critical to the work of professionals within the digital forensic analysis community, as well as the need for immediate response once an incident has been identified. Organized into eight chapters, the book discusses Volume Shadow Copies (VSCs) in the context of digital ...
Read More
Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and postmortem response collection and analysis methodologies for Windows 7. It considers the core investigative and analysis concepts that are critical to the work of professionals within the digital forensic analysis community, as well as the need for immediate response once an incident has been identified. Organized into eight chapters, the book discusses Volume Shadow Copies (VSCs) in the context of digital forensics and explains how analysts can access the wealth of information available in VSCs without interacting with the live system or purchasing expensive solutions. It also describes files and data structures that are new to Windows 7 (or Vista), Windows Registry Forensics, how the presence of malware within an image acquired from a Windows system can be detected, the idea of timeline analysis as applied to digital forensic analysis, and concepts and techniques that are often associated with dynamic malware analysis. Also included are several tools written in the Perl scripting language, accompanied by Windows executables. This book will prove useful to digital forensic analysts, incident responders, law enforcement officers, students, researchers, system administrators, hobbyists, or anyone with an interest in digital forensic analysis of Windows 7 systems.
Read Less
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $2.96, like new condition, Sold by ThriftBooks-Reno rated 5.0 out of 5 stars, ships from Reno, NV, UNITED STATES, published 2012 by Syngress Publishing.
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $2.96, good condition, Sold by ThriftBooks-Dallas rated 5.0 out of 5 stars, ships from Dallas, TX, UNITED STATES, published 2012 by Syngress Publishing.
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $2.96, good condition, Sold by ThriftBooks-Baltimore rated 4.0 out of 5 stars, ships from Halethorpe, MD, UNITED STATES, published 2012 by Syngress Publishing.
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $4.00, fair condition, Sold by HPB-Red rated 5.0 out of 5 stars, ships from Dallas, TX, UNITED STATES, published 2012 by Syngress.
Choose your shipping method in Checkout. Costs may vary based on destination.
Seller's Description:
Fair. Connecting readers with great books since 1972. Used textbooks may not include companion materials such as access codes, etc. May have condition issues including wear and notes/highlighting. We ship orders daily and Customer Service is our top priority!
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $5.24, fair condition, Sold by BooksRun rated 4.0 out of 5 stars, ships from Philadelphia, PA, UNITED STATES, published 2012 by Syngress.
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $28.58, good condition, Sold by Bonita rated 4.0 out of 5 stars, ships from Newport Coast, CA, UNITED STATES, published 2012 by Syngress.
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $32.74, good condition, Sold by TEXTSHUB rated 5.0 out of 5 stars, ships from Franklin Lakes, NJ, UNITED STATES, published 2012 by Syngress.
Add this copy of Windows Forensic Analysis Toolkit: Advanced Analysis to cart. $34.74, good condition, Sold by Book Words rated 4.0 out of 5 stars, ships from Midland Park, NJ, UNITED STATES, published 2012 by Syngress.