Muutke küpsiste eelistusi

E-raamat: Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry

(DFIR analyst, presenter, and open-source tool author)
  • Formaat: EPUB+DRM
  • Ilmumisaeg: 03-Mar-2016
  • Kirjastus: Syngress Media,U.S.
  • Keel: eng
  • ISBN-13: 9780128033357
Teised raamatud teemal:
  • Formaat - EPUB+DRM
  • Hind: 58,68 €*
  • * hind on lõplik, st. muud allahindlused enam ei rakendu
  • Lisa ostukorvi
  • Lisa soovinimekirja
  • See e-raamat on mõeldud ainult isiklikuks kasutamiseks. E-raamatuid ei saa tagastada.
  • Formaat: EPUB+DRM
  • Ilmumisaeg: 03-Mar-2016
  • Kirjastus: Syngress Media,U.S.
  • Keel: eng
  • ISBN-13: 9780128033357
Teised raamatud teemal:

DRM piirangud

  • Kopeerimine (copy/paste):

    ei ole lubatud

  • Printimine:

    ei ole lubatud

  • Kasutamine:

    Digitaalõiguste kaitse (DRM)
    Kirjastus on väljastanud selle e-raamatu krüpteeritud kujul, mis tähendab, et selle lugemiseks peate installeerima spetsiaalse tarkvara. Samuti peate looma endale  Adobe ID Rohkem infot siin. E-raamatut saab lugeda 1 kasutaja ning alla laadida kuni 6'de seadmesse (kõik autoriseeritud sama Adobe ID-ga).

    Vajalik tarkvara
    Mobiilsetes seadmetes (telefon või tahvelarvuti) lugemiseks peate installeerima selle tasuta rakenduse: PocketBook Reader (iOS / Android)

    PC või Mac seadmes lugemiseks peate installima Adobe Digital Editionsi (Seeon tasuta rakendus spetsiaalselt e-raamatute lugemiseks. Seda ei tohi segamini ajada Adober Reader'iga, mis tõenäoliselt on juba teie arvutisse installeeritud )

    Seda e-raamatut ei saa lugeda Amazon Kindle's. 

A guide to the Windows Registry cover such topics as Registry structure, live analysis, security, system hive, and tracking user activity. Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition provides the most in-depth guide to forensic investigations using Windows Registry. This book is one of a kind, giving the background of the Registry to help users develop an understanding of the binary structure of registry hive files.Approaches to live response and analysis are included, and tools and techniques for post mortem analysis are discussed at length. Tools and techniques are presented that take you beyond the current use of viewers and into real analysis of data contained in the Registry.This Second Edition of presents a ground-up approach to understanding so that the treasure trove of the Registry is mined on a regular and continuing basis.Named a Best Digital Forensics Book by InfoSec ReviewsPacked with real-world examples using freely available open source toolsProvides a deep explanation and understanding of the Windows Registry - the most difficult part of Windows to analyze forensicallyIncludes a companion website that contains the code and author-created tools discussed in the bookNew edition completely updated for the most current tools and techniquesContains completely updated content throughout, with all new coverage of the latest versions of Windows

Muu info

The second edition of this go-to reference provides readers with the information, tools, and processes needed to find and analyze forensic evidence using Windows Registry. Tools and techniques for post mortem analysis are discussed at length to take users beyond the current use of viewers and into real analysis of data contained in the Registry.
About the Author ix
About the Technical Editor xi
Preface xiii
Acknowledgments xvi
Chapter 1 Registry Analysis
1(36)
Introduction
1(3)
Core Analysis Concepts
4(11)
What Is the Windows Registry?
15(10)
Registry Structure
25(9)
Summary
34(3)
Chapter 2 Processes and Tools
37(24)
Introduction
37(2)
Forensic Analysis
39(21)
Summary
60(1)
Chapter 3 Analyzing the System Hives
61(70)
Introduction
61(1)
Artifact Categories
62(1)
Security Hive
63(6)
SAM Hive
69(6)
System Hive
75(23)
Software Hive
98(25)
AmCache Hive
123(6)
Summary
129(2)
Chapter 4 Case Studies: User Hives
131(46)
Introduction
131(1)
NTUSER.DAT
132(33)
USRCLASS.DAT
165(9)
Summary
174(3)
Chapter 5 RegRipper
177(16)
Introduction
177(1)
What Is RegRipper?
177(6)
Getting the Most Out of RegRipper
183(8)
Summary
191(2)
Index 193
Mr. Carvey is a digital forensics and incident response analyst with past experience in vulnerability assessments, as well as some limited pen testing. He conducts research into digital forensic analysis of Window systems, identifying and parsing various digital artifacts from those systems, and has developed several innovative tools and investigative processes specific to the digital forensics analysis field. He is the developer of RegRipper, a widely-used tool for Windows Registry parsing and analysis. Mr. Carvey has developed and taught several courses, including Windows Forensics, Registry, and Timeline Analysis.