Windows Registry Forensics, Second Edition: Advanced Digital Forensic Analysis of the Windows Registry
暫譯: Windows 註冊表取證(第二版):Windows 註冊表的進階數位取證分析

Harlan Carvey

  • 出版商: Syngress Media
  • 出版日期: 2016-03-25
  • 售價: $2,450
  • 貴賓價: 9.5$2,328
  • 語言: 英文
  • 頁數: 216
  • 裝訂: Paperback
  • ISBN: 012803291X
  • ISBN-13: 9780128032916
  • 相關分類: 地理資訊系統 Gis
  • 立即出貨 (庫存=1)

買這商品的人也買了...

商品描述

Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition, provides the most in-depth guide to forensic investigations involving Windows Registry. This book is one-of-a-kind, giving the background of the Registry to help users develop an understanding of the structure of registry hive files, as well as information stored within keys and values that can have a significant impact on forensic investigations. Tools and techniques for post mortem analysis are discussed at length to take users beyond the current use of viewers and into real analysis of data contained in the Registry. This second edition continues a ground-up approach to understanding so that the treasure trove of the Registry can be mined on a regular and continuing basis.

  • Named a Best Digital Forensics Book by InfoSec Reviews
  • Packed with real-world examples using freely available open source tools
  • Provides a deep explanation and understanding of the Windows Registry―perhaps the least understood and employed
  • source of information within Windows systems
  • Includes a companion website that contains the code and author-created tools discussed in the book
  • Features updated, current tools and techniques
  • Contains completely updated content throughout, with all new coverage of the latest versions of Windows

商品描述(中文翻譯)

《Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition》提供了對於Windows Registry的法醫調查最深入的指南。本書獨一無二,介紹了Registry的背景,幫助讀者理解註冊檔樹狀檔案的結構,以及存儲在鍵和值中的信息,這些信息對法醫調查有著重要的影響。書中詳細討論了死後分析的工具和技術,幫助讀者超越目前使用的檢視器,進入對Registry中數據的真正分析。這第二版繼續採用從基礎開始的方式來理解,以便能夠定期和持續地挖掘Registry中的寶藏。

- 被InfoSec Reviews評選為最佳數位法醫書籍
- 充滿使用免費開源工具的實際範例
- 提供對Windows Registry的深入解釋和理解——或許是Windows系統中最不被理解和使用的資訊來源
- 包含一個伴隨網站,該網站包含書中討論的代碼和作者創建的工具
- 特別介紹更新的、當前的工具和技術
- 全書內容完全更新,涵蓋最新版本的Windows