Forensic Examination of Windows-Supported File Systems

Doug Elrick, Drew Elrick

  • 出版商: CreateSpace Independ
  • 出版日期: 2014-04-07
  • 售價: $4,220
  • 貴賓價: 9.5$4,009
  • 語言: 英文
  • 頁數: 392
  • 裝訂: Paperback
  • ISBN: 1497358353
  • ISBN-13: 9781497358355
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Understanding the underlying system of how files are stored, what happens when they are deleted, and how to potentially recover them is essential to the digital forensic examiner. Today’s computer forensic tools automate the process of file recovery, but understanding what those tools are accomplishing and knowing whether they are providing accurate results requires an understanding of the information provided in this text. The FAT and NTFS file systems are the most commonly utilized information storage methods and while there are many other methods available, concentrating on these two lays the foundation for learning the others in the future. A brief introduction of ExFAT is included, as it is a relatively new file system used with larger flash drives. Forensic Examination of Windows-Supported File Systems will provide the basis for this knowledge and the practical expertise to begin the journey of becoming a digital forensic scientist.