
Windows Forensic Analysis Toolkit
Advanced Analysis Techniques for Windows 7
Harlan Carvey(Author)
Syngress (Publisher)
3rd Edition
Published on 15. March 2012
Book
Paperback/Softback
296 pages
978-1-59749-727-5 (ISBN)
Article exhausted; check for reprint
Description
Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and postmortem response collection and analysis methodologies for Windows 7. It considers the core investigative and analysis concepts that are critical to the work of professionals within the digital forensic analysis community, as well as the need for immediate response once an incident has been identified. Organized into eight chapters, the book discusses Volume Shadow Copies (VSCs) in the context of digital forensics and explains how analysts can access the wealth of information available in VSCs without interacting with the live system or purchasing expensive solutions. It also describes files and data structures that are new to Windows 7 (or Vista), Windows Registry Forensics, how the presence of malware within an image acquired from a Windows system can be detected, the idea of timeline analysis as applied to digital forensic analysis, and concepts and techniques that are often associated with dynamic malware analysis. Also included are several tools written in the Perl scripting language, accompanied by Windows executables. This book will prove useful to digital forensic analysts, incident responders, law enforcement officers, students, researchers, system administrators, hobbyists, or anyone with an interest in digital forensic analysis of Windows 7 systems.
Reviews / Votes
"Harlan has done it again! Continuing in the tradition of excellence established by the previous editions, Windows Forensics Analysis Toolkit 3e is an indispensable resource for any forensic examiner. Whether you're a seasoned veteran or just starting out, this work is required reading. WFA3e will maintain a perennial spot on my core reference bookshelf!" --Cory Altheide, Google"Windows Forensic Analysis Toolkit 3rd Edition provides a wealth of important information for new and old practitioners alike. Not only does it provide a great overview of artifacts of interest on Windows 7 systems, but it also presents plenty of technology independent concepts that play an important role in any investigation. Feel free to place a copy on your shelf next to WFA 2ed and WRF." --Digital4rensics.com
"The third edition of this reference for system administrators, digital forensic analysts, students, and law enforcement does not replace the second edition, but rather serves as a companion. Coverage encompasses areas such as immediate response, volume shadow copies, file and registry analysis, malware detection, and application analysis. Learning features include b&w screenshots, tip and warning boxes, code (also available on a website), case studies, and 'war stories' from the field. The tools described throughout the book are written in the Perl scripting language, but readers don't need to be experts in Perl, and most of the scripts are accompanied by Windows executables found online. For this third edition, a companion website provides printable checklists, cheat sheets, custom tools, and demos."--Reference and Research Book News, Inc.
"There is a good reason behind the success of the previous editions of this book, and it has to do with two things: new Windows versions are different enough from previous ones to warrant a new edition and, most importantly, the author is simply that good at explaining things. This edition is no different." --HelpNetSecurity
More details
Edition
3rd edition
Language
English
Place of publication
Rockland, MA
United States
Target group
Professional and scholarly
College/higher education
Computer forensic and incident response professionals. This includes LE, federal government, commercial/private sector contractors, consultants, etc.
Illustrations
60 illustrations; Illustrations
Dimensions
Height: 235 mm
Width: 191 mm
Weight
590 gr
ISBN-13
978-1-59749-727-5 (9781597497275)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
New editions

Book
05/2014
4th Edition
Syngress
€68.08
Shipment within 15-20 days

Harlan Carvey
Windows Forensic Analysis DVD Toolkit
Book
09/2009
2nd Edition
Syngress
€82.39
Article exhausted; check for reprint
Additional editions

E-Book
01/2012
3rd Edition
Syngress
€53.95
Available for download
Previous edition

Harlan Carvey
Windows Forensic Analysis DVD Toolkit
Book
09/2009
2nd Edition
Syngress
€82.39
Article exhausted; check for reprint
Person
Mr. Carvey is a digital forensics and incident response analyst with past experience in vulnerability assessments, as well as some limited pen testing. He conducts research into digital forensic analysis of Window systems, identifying and parsing various digital artifacts from those systems, and has developed several innovative tools and investigative processes specific to the digital forensics analysis field. He is the developer of RegRipper, a widely-used tool for Windows Registry parsing and analysis. Mr. Carvey has developed and taught several courses, including Windows Forensics, Registry, and Timeline Analysis.
Content
1. Analysis Concepts
2. Incident Preparation
3. Volume Shadow Copies
4. File Analysis
5. Registry Analysis
6. Malware Detection
7. Timeline Analysis
8. Application Analysis
2. Incident Preparation
3. Volume Shadow Copies
4. File Analysis
5. Registry Analysis
6. Malware Detection
7. Timeline Analysis
8. Application Analysis