
Windows Forensic Analysis Toolkit
Advanced Analysis Techniques for Windows 8
Harlan Carvey(Author)
Syngress (Publisher)
4th Edition
Published on 8. May 2014
Book
Paperback/Softback
350 pages
978-0-12-417157-2 (ISBN)
Description
Harlan Carvey has updated Windows Forensic Analysis Toolkit, now in its fourth edition, to cover Windows 8 systems. The primary focus of this edition is on analyzing Windows 8 systems and processes using free and open-source tools. The book covers live response, file analysis, malware detection, timeline, and much more. Harlan Carvey presents real-life experiences from the trenches, making the material realistic and showing the why behind the how.
The companion and toolkit materials are hosted online. This material consists of electronic printable checklists, cheat sheets, free custom tools, and walk-through demos. This edition complements Windows Forensic Analysis Toolkit, Second Edition, which focuses primarily on XP, and Windows Forensic Analysis Toolkit, Third Edition, which focuses primarily on Windows 7.
This new fourth edition provides expanded coverage of many topics beyond Windows 8 as well, including new cradle-to-grave case examples, USB device analysis, hacking and intrusion cases, and "how would I do this" from Harlan's personal case files and questions he has received from readers. The fourth edition also includes an all-new chapter on reporting.
The companion and toolkit materials are hosted online. This material consists of electronic printable checklists, cheat sheets, free custom tools, and walk-through demos. This edition complements Windows Forensic Analysis Toolkit, Second Edition, which focuses primarily on XP, and Windows Forensic Analysis Toolkit, Third Edition, which focuses primarily on Windows 7.
This new fourth edition provides expanded coverage of many topics beyond Windows 8 as well, including new cradle-to-grave case examples, USB device analysis, hacking and intrusion cases, and "how would I do this" from Harlan's personal case files and questions he has received from readers. The fourth edition also includes an all-new chapter on reporting.
Reviews / Votes
"... this book is well written and easy to read...has some material of interest to experts..."--Computing Reviews, Windows Forensic Analysis Toolkit, 4th Edition"...technical detail is extensive here and those realworld examples mentioned earlier are worked through in intricate detail. You will definitely want to try this at home..." -Network Security, Nov 2014
More details
Edition
4th edition
Language
English
Place of publication
Rockland, MA
United States
Target group
Professional and scholarly
Information Security professionals of all levels, digital forensic examiners and investigators, InfoSec consultants, attorneys, law enforcement officers. Also can sell to forensic training vendors, government training courses, universities, and high-tech crime associations.
Illustrations
60 illustrations; Illustrations
Dimensions
Height: 235 mm
Width: 191 mm
Weight
720 gr
ISBN-13
978-0-12-417157-2 (9780124171572)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
Additional editions

E-Book
03/2014
4th Edition
Syngress
€53.95
Available for download
Previous edition

Book
03/2012
3rd Edition
Syngress
€79.41
Article exhausted; check for reprint
Person
Mr. Carvey is a digital forensics and incident response analyst with past experience in vulnerability assessments, as well as some limited pen testing. He conducts research into digital forensic analysis of Window systems, identifying and parsing various digital artifacts from those systems, and has developed several innovative tools and investigative processes specific to the digital forensics analysis field. He is the developer of RegRipper, a widely-used tool for Windows Registry parsing and analysis. Mr. Carvey has developed and taught several courses, including Windows Forensics, Registry, and Timeline Analysis.
Content
Analysis Concepts
Immediate Response
Volume Shadow Copies
File Analysis
Registry Analysis
Malware Detection
Timeline Analysis
Application Analysis
Reporting
Immediate Response
Volume Shadow Copies
File Analysis
Registry Analysis
Malware Detection
Timeline Analysis
Application Analysis
Reporting