Book description
This book is your comprehensive guide to Windows forensics. It covers the process of conducting or performing a forensic investigation of systems that run on Windows operating systems. It also includes analysis of incident response, recovery, and auditing of equipment used in executing any criminal activity.
The book covers Windows registry, architecture, and systems as well as forensic techniques, along with coverage of how to write reports, legal standards, and how to testify. It starts with an introduction to Windows followed by forensic concepts and methods of creating forensic images. You will learn Windows file artefacts along with Windows Registry and Windows Memory forensics. And you will learn to work with PowerShell scripting for forensic applications and Windows email forensics. Microsoft Azure and cloud forensics are discussed and you will learn how to extract from the cloud. By the end of the book you will know data-hiding techniques in Windows and learn about volatility and a Windows Registry cheat sheet.
What Will You Learn
- Understand Windows architecture
- Recover deleted files from Windows and the recycle bin
- Use volatility and PassMark volatility workbench
- Utilize Windows PowerShell scripting for forensic applications
Who This Book Is For
Windows administrators, forensics practitioners, and those wanting to enter the field of digital forensics
Table of contents
- Cover
- Front Matter
- 1. Introduction to Windows
- 2. Forensics Concepts
- 3. Creating Forensic Images Using OSForensics, FTK Imager, and Autopsy
- 4. Windows File Artifacts
- 5. Windows Registry Forensics Part 1
- 6. Windows Registry Forensics Part 2
- 7. Windows Shadow Copy
- 8. Windows Memory Forensics
- 9. PowerShell Forensics
- 10. Web Browser Forensics
- 11. Windows Email Forensics
- 12. Microsoft Azure and Cloud Forensics
- 13. Data Hiding Techniques in Windows
- Back Matter
Product information
- Title: Windows Forensics: Understand Analysis Techniques for Your Windows
- Author(s):
- Release date: May 2024
- Publisher(s): Apress
- ISBN: 9798868801938
You might also like
book
Windows Forensics Analyst Field Guide
Build your expertise in Windows incident analysis by mastering artifacts and techniques for efficient cybercrime investigation …
book
Practical Windows Forensics
Leverage the power of digital forensics for Windows systems About This Book Build your own lab …
book
Windows Security Internals
Windows Security Internals is a must-have for anyone needing to understand the Windows operating system's low-level …
book
Pentesting Active Directory and Windows-based Infrastructure
Enhance your skill set to pentest against real-world Microsoft infrastructure with hands-on exercises and by following …