?If your job requires investigating compromised Windows hosts, you must read Windows Forensic Analysis.?
?Richard Bejtlich, Coauthor of Real Digital Forensics and Amazon.com Top 500 Book Reviewer
?The Registry Analysis chapter alone is worth the price of the book.?
?Troy Larson, Senior Forensic Investigator of Microsoft?s IT Security Group
?I also found that the entire book could have been written on just registry forensics. However, in order to create broad appeal, the registry section was probably shortened. You can tell Harlan has a lot more to tell.?
?Rob Lee, Instructor and Fellow at the SANS Technology Institute, coauthor of Know Your Enemy: Learning About Security Threats, 2E
Windows Forensic Analysis DVD Toolkit, 2E replaces the first edition as the most comprehensive and thorough resource on incident response and forensic analysis of Windows systems available, providing information and resources not available anywhere else. This book covers both live and post-mortem response collection and analysis methodologies, addressing material that is applicable to law enforcement, the federal government, students, and consultants. It also brings this material to the doorstep of system administrators, who are often the frontline troops when an incident occurs, but due to staffing and budgets do not have the necessary knowledge to respond effectively. The companion DVD contains significant new and updated materials (movies, spreadsheet, code, etc.) not available any place else, because they were created and maintained by the author.
In the two years since the first edition was originally published, cybercrime has continued to increase, and the criminals committing the crimes have continued to become more sophisticated. Analysts and investigators need up-to-date information to stay one step ahead, whether they?re examining a system for signs of an intrusion or a data breach. Also, state and federal legislation (e.g., CA-1386), as well as standards issued by regulatory bodies (e.g., PCI and HIPAA), are adding an entirely new dimension to what was once thought to be solely the domain of IT staff. Incident responders and forensic analysts now have a whole new set of questions to answer, and the only way to answer them is to be armed the latest and most up-to-date information and analysis techniques, all of which are covered in detail in this critical update of the best-selling resource.
* Based on reviewer feedback, the most popular chapter of the book, ?Registry Analysis,? is thoroughly upgraded and expanded with a completely new set of unique tools developed and demonstrated by the author.
* A brand-new chapter, ?Forensic Analysis on a Budget,? collects freely available tools that are essential for small labs, state (or below) law enforcement, and educational organizations that can?t afford bloated and expensive application suites.
* Completely new chapter ?Tying It All Together? puts the otherwise isolated concepts in the book into context of incident response and addresses frequent questions posed in public lists and forums.
* Once something a responder should do, developments in 2008 made Windows memory analysis a more sophisticated and important requirement that is given increased detail and focus in the new version of the chapter in this book.
* New pedagogical elements??Lessons from the Field,? ?Case Studies,? and ?War Stories??present real-life experiences from the trenches by an expert in the trenches, making the material real and showing the why behind the how.
* The companion DVD contains new, significant, and unique materials (movies, spreadsheet, code, etc.) not available any place else, because they were created by the author.
"synopsis" may belong to another edition of this title.
Harlan Carvey developed an interest in computer security while in the military. After leaving active duty, he began working in the area of penetration testing and vulnerability assessments, leading teams of engineers, and developing his own tools to optimize his ability to collect and analyze data. As most clients employed Windows to some degree, Harlan began to see a disparity in knowledge and support for these operating systems, and decided to seize the opportunity and focus on Windows as an area of interest and research. This led him to address topics in incident response and forensic analysis, and to his position as a forensic analyst.
Harlan has been a prolific author and presenter, beginning with the Usenix LISA-NT conference in 2000. He has also presented at Black Hat, DefCon 9, MISTI, and HTCIA/GMU conferences. Harlan has had articles published in the Information Security Bulletin as well as on the SecurityFocus web site, and is the author of "Windows Forensics and Incident Recovery."
Windows Forensic Analysis DVD Toolkit, Second Edition, is a completely updated and expanded version of Harlan Carvey's best-selling forensics book on incident response and investigating cybercrime on Windows systems. With this book, you will learn how to analyze data during live and post-mortem investigations.
New to this edition is Forensic Analysis on a Budget, which collects freely available tools that are essential for small labs, state (or below) law enforcement, and educational organizations. The book also includes new pedagogical elements, Lessons from the Field, Case Studies, and War Stories that present real-life experiences by an expert in the trenches, making the material real and showing the why behind the how. The companion DVD contains significant, and unique, materials (movies, spreadsheet, code, etc.) not available anyplace else because they were created by the author.
This book will appeal to digital forensic investigators, IT security professionals, engineers, and system administrators as well as students and consultants.
"About this title" may belong to another edition of this title.
FREE shipping within United Kingdom
Destination, rates & speeds£ 22.36 shipping from U.S.A. to United Kingdom
Destination, rates & speedsSeller: Better World Books Ltd, Dunfermline, United Kingdom
Condition: Very Good. 2 Edition. Ships from the UK. Former library book; may include library markings. Used book that is in excellent condition. May show signs of wear or have minor defects. Seller Inventory # GRP67605884
Quantity: 2 available
Seller: WorldofBooks, Goring-By-Sea, WS, United Kingdom
Paperback. Condition: Very Good. The book has been read, but is in excellent condition. Pages are intact and not marred by notes or highlighting. The spine remains undamaged. Seller Inventory # GOR004876330
Quantity: 1 available
Seller: Phatpocket Limited, Waltham Abbey, HERTS, United Kingdom
Condition: Good. Your purchase helps support Sri Lankan Children's Charity 'The Rainbow Centre'. Ex-library, so some stamps and wear, but in good overall condition. Our donations to The Rainbow Centre have helped provide an education and a safe haven to hundreds of children who live in appalling conditions. Seller Inventory # Z1-C-032-01776
Quantity: 1 available
Seller: Better World Books, Mishawaka, IN, U.S.A.
Condition: Very Good. 2 Edition. Used book that is in excellent condition. May show signs of wear or have minor defects. Seller Inventory # 9031016-20
Quantity: 1 available
Seller: Better World Books, Mishawaka, IN, U.S.A.
Condition: Good. 2 Edition. Former library book; may include library markings. Used book that is in clean, average condition without any missing pages. Seller Inventory # 15365223-20
Quantity: 1 available
Seller: Better World Books, Mishawaka, IN, U.S.A.
Condition: Good. 2 Edition. Used book that is in clean, average condition without any missing pages. Seller Inventory # 4153747-20
Quantity: 1 available
Seller: ThriftBooks-Dallas, Dallas, TX, U.S.A.
Paperback. Condition: Good. No Jacket. Pages can have notes/highlighting. Spine may show signs of wear. ~ ThriftBooks: Read More, Spend Less 1.01. Seller Inventory # G1597494224I3N00
Quantity: 1 available
Seller: ThriftBooks-Dallas, Dallas, TX, U.S.A.
Paperback. Condition: As New. No Jacket. Pages are clean and are not marred by notes or folds of any kind. ~ ThriftBooks: Read More, Spend Less 1.01. Seller Inventory # G1597494224I2N00
Quantity: 1 available
Seller: ThriftBooks-Atlanta, AUSTELL, GA, U.S.A.
Paperback. Condition: Very Good. No Jacket. May have limited writing in cover pages. Pages are unmarked. ~ ThriftBooks: Read More, Spend Less 1.01. Seller Inventory # G1597494224I4N00
Quantity: 1 available
Seller: ThriftBooks-Dallas, Dallas, TX, U.S.A.
Paperback. Condition: Very Good. No Jacket. May have limited writing in cover pages. Pages are unmarked. ~ ThriftBooks: Read More, Spend Less 1.01. Seller Inventory # G1597494224I4N00
Quantity: 1 available