Windows Forensic Analysis Toolkite : Advanced Analysis Techniques for Windows 8 (Paperback) 4/e
暫譯: Windows 取證分析工具包:Windows 8 的進階分析技術 (平裝) 第 4 版

Harlan Carvey

  • 出版商: Syngress Media
  • 出版日期: 2014-03-27
  • 售價: $2,730
  • 貴賓價: 9.5$2,594
  • 語言: 英文
  • 頁數: 350
  • 裝訂: Paperback
  • ISBN: 0124171575
  • ISBN-13: 9780124171572
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

相關主題

商品描述

Harlan Carvey has updated Windows Forensic Analysis Toolkit, now in its fourth edition, to cover Windows 8 systems. The primary focus of this edition is on analyzing Windows 8 systems and processes using free and open-source tools. The book covers live response, file analysis, malware detection, timeline, and much more. Harlan Carvey presents real-life experiences from the trenches, making the material realistic and showing the why behind the how.

The companion and toolkit materials are hosted online. This material consists of electronic printable checklists, cheat sheets, free custom tools, and walk-through demos. This edition complements Windows Forensic Analysis Toolkit, Second Edition, which focuses primarily on XP, and Windows Forensic Analysis Toolkit, Third Edition, which focuses primarily on Windows 7.

This new fourth edition provides expanded coverage of many topics beyond Windows 8 as well, including new cradle-to-grave case examples, USB device analysis, hacking and intrusion cases, and "how would I do this" from Harlan's personal case files and questions he has received from readers. The fourth edition also includes an all-new chapter on reporting.

  • Complete coverage and examples of Windows 8 systems
  • Contains lessons from the field, case studies, and war stories
  • Companion online toolkit material, including electronic printable checklists, cheat sheets, custom tools, and walk-throughs

商品描述(中文翻譯)

Harlan Carvey 更新了《Windows 取證分析工具包》(Windows Forensic Analysis Toolkit),現在已進入第四版,涵蓋 Windows 8 系統。本版的主要重點是使用免費和開源工具分析 Windows 8 系統和過程。這本書涵蓋了即時回應、檔案分析、惡意程式檢測、時間線等多個主題。Harlan Carvey 以實際經驗為基礎,使材料更具現實感,並展示了「如何」背後的「為什麼」。

伴隨的工具包材料在線上提供。這些材料包括可列印的電子檢查清單、備忘單、免費自訂工具和逐步演示。本版補充了《Windows 取證分析工具包,第二版》,該版主要集中於 XP,以及《Windows 取證分析工具包,第三版》,該版主要集中於 Windows 7。

這個全新的第四版還擴展了許多主題的涵蓋範圍,不僅限於 Windows 8,包括新的從搖籃到墳墓的案例示例、USB 設備分析、駭客和入侵案例,以及來自 Harlan 個人案例檔案的「我會如何做這個」問題和讀者提出的問題。第四版還新增了一章關於報告的內容。

- 完整涵蓋和示例 Windows 8 系統
- 包含來自現場的教訓、案例研究和戰爭故事
- 伴隨的在線工具包材料,包括可列印的電子檢查清單、備忘單、自訂工具和逐步演示