LEADER 02470nam 2200433 450 001 9910583352003321 005 20230120002803.0 010 $a0-12-811416-9 035 $a(CKB)4100000005879321 035 $a(CaSebORM)9780128114162 035 $a(MiAaPQ)EBC5493879 035 $a(EXLCZ)994100000005879321 100 $a20180907d2018 uy 0 101 0 $aeng 135 $aurcnu|||||||| 181 $ctxt$2rdacontent 182 $cc$2rdamedia 183 $acr$2rdacarrier 200 10$aInvestigating windows systems /$fHarlan Carvey 205 $a1st edition 210 1$aLondon, England :$cAcademic Press,$d2018. 215 $a1 online resource (137 pages) 311 $a0-12-811415-0 330 $aUnlike other books, courses and training that expect an analyst to piece together individual instructions into a cohesive investigation, Investigating Windows Systems provides a walk-through of the analysis process, with descriptions of the thought process and analysis decisions along the way. Investigating Windows Systems will not address topics which have been covered in other books, but will expect the reader to have some ability to discover the detailed usage of tools and to perform their own research. The focus of this volume is to provide a walk-through of the analysis process, with descriptions of the thought process and the analysis decisions made along the way. A must-have guide for those in the field of digital forensic analysis and incident response. Provides the reader with a detailed walk-through of the analysis process, with decision points along the way, assisting the user in understanding the resulting data Coverage will include malware detection, user activity, and how to set up a testing environment Written at a beginner to intermediate level for anyone engaging in the field of digital forensic analysis and incident response 606 $aElectronic data processing$xBackup processing alternatives 606 $aData recovery (Computer science) 606 $aProceso electrónico de datos 615 0$aElectronic data processing$xBackup processing alternatives. 615 0$aData recovery (Computer science) 615 04$aProceso electrónico de datos 676 $a005.86 700 $aCarvey$b Harlan$0523172 801 0$bMiAaPQ 801 1$bMiAaPQ 801 2$bMiAaPQ 906 $aBOOK 912 $a9910583352003321 996 $aInvestigating windows systems$91933234 997 $aUNINA