Windows Forensics is the most comprehensive and up-to-date resource for those wishing to leverage the power of Linux and free software in order to quickly and efficiently perform forensics on Windows systems. It is also a great asset for anyone that would like to better understand Windows internals.
Windows Forensics will guide you step by step through the process of investigating a computer running Windows. Whatever the reason for performing forensics on a Windows system, be it incident response, a criminal investigation, suspected data ex-filtration, or data recovery, this book will tell you what you need to know in order to perform the vast majority of investigations. All of the tools discussed in this book are free and most are also open source.
Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Windows systems. While readers will have a strong grasp of Python and shell scripting by the time they complete this book, no prior knowledge of either of these scripting languages is assumed. Windows Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images.
Windows Forensics contains extensive coverage of Windows FAT and NTFS filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. The treasure trove of data found in the Windows Registry and other artifacts are discussed in detail. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussion of malware analysis rounds out the book.
Book Highlights
554 pages in large, easy-to-read 8.5 x 11 inch format
Over 11,000 lines of Python scripts with explanations
Over 500 lines of shell and command scripts with explanations
A 96 page chapter covering the FAT filesystem in detail
A 164 page chapter on NTFS filesystems
Multiple scenarios described in detail with images available from the book website
All scripts and other support files are available from the book website
"synopsis" may belong to another edition of this title.
Dr. Philip Polstra (known to his friends as Dr. Phil) is an internationally recognized hardware hacker. His work has been presented at numerous conferences around the globe including repeat performances at DEFCON (seven presentations in five consecutive years), BlackHat, 44CON, GrrCON, MakerFaire, ForenSecure, and other top conferences. Dr. Polstra is a well-known expert on USB forensics and has published several articles on this topic. He has developed a number of video courses including ones on Windows forensics, Linux forensics, USB forensics, and reverse engineering. Dr. Polstra has developed degree programs in digital forensics and ethical hacking while serving as a professor and Hacker in Residence at a private university in the Midwestern United States. He currently teaches in one of the top Digital Forensics degree programs in the United States at Bloomsburg University of Pennsylvania. In addition to teaching, he provides training and performs penetration tests on a consulting basis. When not working, he has been known to fly, build aircraft, and tinker with electronics. He is an accomplished aviator with thousands of hours of flight time and a dozen ratings as a pilot, flight instructor, mechanic, aircraft inspector, and avionics specialist. His latest happenings can be found on his website http://philpolstra.com. You can also follow him at @ppolstra on Twitter. Dr. Polstra authored Hacking and Penetration Testing with Low Power Devices (Syngress, 2014) in which he showed the world how to easily build drop boxes, hacking consoles, and remote hacking drones with the BeagleBone Black and similar devices. Techniques described in this book permit security penetration tests to be performed with multiple, possibly battery powered, devices which are controlled by a user up to two miles away from the target organization. His book, Linux Forensics (Pentester Academy, 2015), is the most comprehensive and up-to-date resource available to anyone wishing to perform forensics on Linux systems. The first printing of this book sold out in under twenty five hours. This book is considered a must have by a number of forensic investigators around the world. His latest book, Windows Forensics (Pentester Academy, 2016), is the top resource available to anyone wishing to perform forensics on Windows systems. This book brings forensics to the masses by showing them how to leverage the power of Linux and free software to perform forensics on Windows systems.
"About this title" may belong to another edition of this title.
Seller: Zoom Books Company, Lynden, WA, U.S.A.
Condition: very_good. Book is in very good condition and may include minimal underlining highlighting. The book can also include "From the library of" labels. May not contain miscellaneous items toys, dvds, etc. . We offer 100% money back guarantee and 24 7 customer service. Seller Inventory # ZBV.1535312432.VG
Seller: Books for Life, LAUREL, MD, U.S.A.
Condition: acceptable. Book is in acceptable condition. May have shelf wear, edge wear, and spine wear, but a very readable copy. May not come with supplemental materials if applicable. Does not include original dustcover jacket. Possibly Ex Library Copy. Seller Inventory # LFM.5U2X
Seller: ThriftBooks-Atlanta, AUSTELL, GA, U.S.A.
Paperback. Condition: Very Good. No Jacket. May have limited writing in cover pages. Pages are unmarked. ~ ThriftBooks: Read More, Spend Less. Seller Inventory # G1535312432I4N00
Seller: ThriftBooks-Dallas, Dallas, TX, U.S.A.
Paperback. Condition: Fair. No Jacket. Readable copy. Pages may have considerable notes/highlighting. ~ ThriftBooks: Read More, Spend Less. Seller Inventory # G1535312432I5N00
Seller: SVFOL Bookstore, Sierra Vista, AZ, U.S.A.
paperback. Condition: Very Good. LIKE NEW / VERY GOOD - No creases or tears on spine and/or cover LIKE NEW / VERY GOOD - No missing or damaged pages LIKE NEW / VERY GOOD - No text or writing on the pages or in the margins LIKE NEW / VERY GOOD - No underlining or highlighting of text VERY GOOD - Cover has very minimal wear and tear with no obvious damage VERY GOOD - Zero to Limited corner dings and/or curled corners All items shipped Monday - Friday, fast shipping! Proceeds support the Sierra Vista Public Library. Seller Inventory # mon0000001287
Seller: medimops, Berlin, Germany
Condition: good. Befriedigend/Good: Durchschnittlich erhaltenes Buch bzw. Schutzumschlag mit Gebrauchsspuren, aber vollständigen Seiten. / Describes the average WORN book or dust jacket that has all the pages present. Seller Inventory # M01535312432-G
Seller: GreatBookPrices, Columbia, MD, U.S.A.
Condition: As New. Unread book in perfect condition. Seller Inventory # 27050884
Seller: GreatBookPrices, Columbia, MD, U.S.A.
Condition: New. Seller Inventory # 27050884-n
Seller: Rarewaves USA, OSWEGO, IL, U.S.A.
Paperback. Condition: New. 1st. Seller Inventory # LU-9781535312431
Seller: GoldBooks, Denver, CO, U.S.A.
Paperback. Condition: new. New Copy. Customer Service Guaranteed. Seller Inventory # 8T32_53_1535312432