Windows Registry Forensics, Second Edition: Advanced Digital Forensic Analysis of the Windows Registry

Harlan Carvey

  • 出版商: Syngress Media
  • 出版日期: 2016-03-25
  • 售價: $2,450
  • 貴賓價: 9.5$2,328
  • 語言: 英文
  • 頁數: 216
  • 裝訂: Paperback
  • ISBN: 012803291X
  • ISBN-13: 9780128032916
  • 相關分類: 地理資訊系統 Gis
  • 立即出貨 (庫存=1)

買這商品的人也買了...

商品描述

Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition, provides the most in-depth guide to forensic investigations involving Windows Registry. This book is one-of-a-kind, giving the background of the Registry to help users develop an understanding of the structure of registry hive files, as well as information stored within keys and values that can have a significant impact on forensic investigations. Tools and techniques for post mortem analysis are discussed at length to take users beyond the current use of viewers and into real analysis of data contained in the Registry. This second edition continues a ground-up approach to understanding so that the treasure trove of the Registry can be mined on a regular and continuing basis.

  • Named a Best Digital Forensics Book by InfoSec Reviews
  • Packed with real-world examples using freely available open source tools
  • Provides a deep explanation and understanding of the Windows Registry―perhaps the least understood and employed
  • source of information within Windows systems
  • Includes a companion website that contains the code and author-created tools discussed in the book
  • Features updated, current tools and techniques
  • Contains completely updated content throughout, with all new coverage of the latest versions of Windows

商品描述(中文翻譯)

《Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry, Second Edition》是一本提供最深入指南的書籍,用於涉及Windows Registry的法醫調查。這本書獨一無二,提供了Registry的背景,幫助用戶了解Registry hive文件的結構,以及存儲在鍵和值中的信息,這些信息對法醫調查具有重要影響。書中詳細討論了事後分析的工具和技術,使用戶不僅僅局限於查看器的使用,而是真正分析Registry中的數據。第二版繼續從頭開始進行理解,以便能夠定期和持續地開採Registry的寶藏。


  • 被InfoSec Reviews評為最佳數位取證書籍

  • 使用免費開源工具的真實案例豐富

  • 深入解釋和理解Windows Registry,可能是最不被理解和使用的Windows系統中的信息來源

  • 包含一個附帶網站,其中包含書中討論的代碼和作者創建的工具

  • 更新且當前的工具和技術

  • 全書內容完全更新,包括對最新版本Windows的全新覆蓋