Windows Forensics Cookbook
Oleg Skulkin, Scar de Courcier
- 出版商: Packt Publishing
- 出版日期: 2017-08-04
- 售價: $1,970
- 貴賓價: 9.5 折 $1,872
- 語言: 英文
- 頁數: 274
- 裝訂: Paperback
- ISBN: 1784390496
- ISBN-13: 9781784390495
海外代購書籍(需單獨結帳)
買這商品的人也買了...
相關主題
商品描述
Key Features
- Prepare and perform investigations using powerful tools for Windows,
- Collect and validate evidence from suspect networks and computers and uncover clues that are otherwise difficult
- Packed with powerful recipes to perform highly effective field investigations
Book Description
This book covers recipes to overcome these challenges and carry out effective investigations easily on a Windows platform. You will begin with a refresher to Digital Forensics and Evidence Acquisition, which will help you to understand the challenges faced while acquiring evidence from Windows systems. Next you will learn to acquire Windows memory and and analyze Windows systems with modern forensic tools. The book will also cover more in-depth elements of forensic analysis, such as how to analyse data from Windows system artifacts, parsing data from the most commonly-used web browsers and email services, and effective reporting in digital forensic investigations.
You will get to know how Windows 10 is different from previous versions and how you can overcome the specific challenges it brings. Finally, you will learn to troubleshoot issues that arise while performing digital forensic investigations.
By the end of the book, you will be able to carry forensics investigations efficiently.
What you will learn
- Understand Challenges of Acquiring Evidence from Windows Systems and overcome them
- Acquire and analyze Windows Memory and Drive with modern forensic tools.
- Extract and analyze data from Windows file systems, shadow copies and the registry
- Understand the main Windows system artifacts and how to parse data from them using forensic tools
- Forensic analysis of common web browsers, mailboxes and instant messenger services
- How Windows 10 differs from previous versions and how to overcome the specific challenges it presents
- Create a graphical timeline and visualize data, which can then be incorporated into the final report
- Troubleshoot issues that arise while performing Windows forensics
商品描述(中文翻譯)
關鍵特點
- 使用強大的工具為 Windows 準備和執行調查
- 從可疑的網路和電腦中收集和驗證證據,並揭示其他難以發現的線索
- 包含強大的配方,以執行高效的現場調查
書籍描述
本書涵蓋了克服這些挑戰的配方,並在 Windows 平台上輕鬆進行有效的調查。您將從數位取證和證據獲取的回顧開始,這將幫助您理解在從 Windows 系統獲取證據時所面臨的挑戰。接下來,您將學習如何獲取 Windows 記憶體並使用現代取證工具分析 Windows 系統。本書還將深入探討取證分析的更多元素,例如如何分析來自 Windows 系統工件的數據、解析來自最常用的網頁瀏覽器和電子郵件服務的數據,以及在數位取證調查中的有效報告。
您將了解 Windows 10 與先前版本的不同之處,以及如何克服它所帶來的特定挑戰。最後,您將學習在執行數位取證調查時如何排除出現的問題。
在本書結束時,您將能夠高效地進行取證調查。
您將學到的內容
- 理解從 Windows 系統獲取證據的挑戰並克服它們
- 使用現代取證工具獲取和分析 Windows 記憶體和驅動器
- 從 Windows 檔案系統、影像副本和登錄檔中提取和分析數據
- 理解主要的 Windows 系統工件以及如何使用取證工具解析數據
- 對常見網頁瀏覽器、郵箱和即時通訊服務進行取證分析
- Windows 10 與先前版本的不同之處以及如何克服其特定挑戰
- 創建圖形時間線並可視化數據,然後將其納入最終報告
- 排除在執行 Windows 取證時出現的問題