Windows Forensics
暫譯: Windows 取證分析
Dr. Philip Polstra
- 出版商: CreateSpace Independ
- 出版日期: 2016-07-16
- 售價: $1,870
- 貴賓價: 9.5 折 $1,777
- 語言: 英文
- 頁數: 554
- 裝訂: Paperback
- ISBN: 1535312432
- ISBN-13: 9781535312431
立即出貨 (庫存 < 3)
買這商品的人也買了...
-
$1,750$1,663 -
$2,450$2,328
商品描述
Windows Forensics is the most comprehensive and up-to-date resource for those wishing to leverage the power of Linux and free software in order to quickly and efficiently perform forensics on Windows systems. It is also a great asset for anyone that would like to better understand Windows internals.
Windows Forensics will guide you step by step through the process of investigating a computer running Windows. Whatever the reason for performing forensics on a Windows system, be it incident response, a criminal investigation, suspected data ex-filtration, or data recovery, this book will tell you what you need to know in order to perform the vast majority of investigations. All of the tools discussed in this book are free and most are also open source.
Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Windows systems. While readers will have a strong grasp of Python and shell scripting by the time they complete this book, no prior knowledge of either of these scripting languages is assumed. Windows Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images.
Windows Forensics contains extensive coverage of Windows FAT and NTFS filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. The treasure trove of data found in the Windows Registry and other artifacts are discussed in detail. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussion of malware analysis rounds out the book.
Book Highlights
- 554 pages in large, easy-to-read 8.5 x 11 inch format
- Over 11,000 lines of Python scripts with explanations
- Over 500 lines of shell and command scripts with explanations
- A 96 page chapter covering the FAT filesystem in detail
- A 164 page chapter on NTFS filesystems
- Multiple scenarios described in detail with images available from the book website
- All scripts and other support files are available from the book website
商品描述(中文翻譯)
Windows Forensics 是一本最全面且最新的資源,適合希望利用 Linux 和免費軟體的力量,快速且有效地對 Windows 系統進行取證的人士。對於任何希望更好地理解 Windows 內部運作的人來說,這本書也是一個極好的資產。
Windows Forensics 將逐步指導您調查運行 Windows 的計算機。無論進行 Windows 系統取證的原因是事件響應、刑事調查、懷疑數據外洩或數據恢復,本書都會告訴您執行大多數調查所需的知識。本書中討論的所有工具都是免費的,且大多數也是開源的。
Philip Polstra 博士展示了如何利用多種工具,如 Python、Shell 腳本和 MySQL,快速、輕鬆且準確地分析 Windows 系統。雖然讀者在完成本書後將對 Python 和 Shell 腳本有深入的理解,但不假設讀者對這兩種腳本語言有任何先前的知識。Windows Forensics 開始時會教您如何使用最小侵入性技術來判斷是否發生了事件。一旦看起來可能發生了事件,Polstra 博士將指導您如何在關閉系統以創建檔案系統映像之前,從運行中的系統收集數據。
Windows Forensics 詳細涵蓋了 Windows FAT 和 NTFS 檔案系統。本書中提供了大量用於創建、掛載和分析檔案系統映像的 Python 和 Shell 腳本。Windows 註冊表和其他文物中發現的豐富數據也會詳細討論。Polstra 博士向讀者介紹了使用 Volatility 框架進行內存分析的令人興奮的新領域。對於惡意軟體分析的討論為本書畫上了句號。
書籍亮點
- 554 頁,採用大型、易讀的 8.5 x 11 英寸格式
- 超過 11,000 行的 Python 腳本及其解釋
- 超過 500 行的 Shell 和命令腳本及其解釋
- 一個 96 頁的章節詳細介紹 FAT 檔案系統
- 一個 164 頁的章節介紹 NTFS 檔案系統
- 多個場景詳細描述,並可從書籍網站獲取圖片
- 所有腳本和其他支援文件均可從書籍網站獲取