Windows Forensic Analysis Toolkit et plus d'un million d'autres livres sont disponibles pour le Kindle d'Amazon. En savoir plus
EUR 53,75
  • Tous les prix incluent la TVA.
Il ne reste plus que 2 exemplaire(s) en stock (d'autres exemplaires sont en cours d'acheminement).
Expédié et vendu par Amazon.
Emballage cadeau disponible.
Quantité :1
Windows Forensic Analysis... a été ajouté à votre Panier
Vous l'avez déjà ?
Repliez vers l'arrière Repliez vers l'avant
Ecoutez Lecture en cours... Interrompu   Vous écoutez un extrait de l'édition audio Audible
En savoir plus
Voir les 2 images

Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 8 (Anglais) Broché – 8 mai 2014

Voir les 2 formats et éditions Masquer les autres formats et éditions
Prix Amazon Neuf à partir de Occasion à partir de
Format Kindle
"Veuillez réessayer"
"Veuillez réessayer"
EUR 53,75
EUR 48,06 EUR 47,59

Offres spéciales et liens associés

Descriptions du produit

Biographie de l'auteur

Harlan Carvey (CISSP) is a Vice President of Advanced Security Projects with Terremark Worldwide, Inc. Terremark is a leading global provider of IT infrastructure and "cloud computing” services, based in Miami, FL. Harlan is a key contributor to the Engagement Services practice, providing disk forensics analysis, consulting, and training services to both internal and external customers. Harlan has provided forensic analysis services for the hospitality industry, financial institutions, as well as federal government and law enforcement agencies. Harlan's primary areas of interest include research and development of novel analysis solutions, with a focus on Windows platforms.
Harlan holds a bachelor's degree in electrical engineering from the Virginia Military Institute and a master's degree in the same discipline from the Naval Postgraduate School. Harlan resides in Northern Virginia with his family.

Détails sur le produit

En savoir plus sur l'auteur

Découvrez des livres, informez-vous sur les écrivains, lisez des blogs d'auteurs et bien plus encore.

Dans ce livre (En savoir plus)
Parcourir les pages échantillon
Couverture | Copyright | Table des matières | Extrait | Index
Rechercher dans ce livre:

Quels sont les autres articles que les clients achètent après avoir regardé cet article?

Commentaires en ligne

Il n'y a pas encore de commentaires clients sur
5 étoiles
4 étoiles
3 étoiles
2 étoiles
1 étoiles

Commentaires client les plus utiles sur (beta) 8 commentaires
18 internautes sur 20 ont trouvé ce commentaire utile 
Disappointing Update to Windows Forensic Analysis 30 avril 2014
Par Rob Lee - Publié sur
Format: Format Kindle Achat vérifié
I am a fan of Harlan's books and we even carry them in the SANS bookstore at conference events as recommended reading by SANS instructors. His last book "Windows Forensic Analysis: Advanced Analysis Techniques for Windows 7" was a wonderful rewrite and included many new artifacts found on Windows 7 including jumplists, volume shadow copy, and many new registry keys.

This new book, is basically a reprint of his previous book based on Windows 7 with some brief mentions of Windows 8 artifacts. Harlan does mention this fact even in the book, but I feel the title is a bit misleading especially if you have a copy of his previous book.

If you have already purchased his 3rd edition book, I would pass on this book until more Windows 8 artifacts are detailed in full. Having read the book in full including the last two new chapters, it does include some brief new artifacts for Windows 8, but not enough to warrant spending the money to update your library at this point.

The book is great if the majority of your analysis is on Windows 7 systems. If you don't have a copy of the 3rd edition, then this book is a great addition to your forensics library. However, due the the misleading title "Advanced Analysis Techniques for Windows 8," I cannot rate the version of the book any higher.
2 internautes sur 2 ont trouvé ce commentaire utile 
Should be required reading for Forensic Examiners 20 mai 2014
Par Mari DeGrazia - Publié sur
Format: Broché
This book is well written, full of tips, and teaches the methodology of forensic examinations rather than just “go look here for this artifact”. Case in point is the Timeline chapter. This chapter does a great job of explaining the benefits of creating a timeline, and even walks the reader through the process using a Windows XP image.

The chapter on report writing was extremely helpful. In my experience, this is one area that many examiners may struggle with, because without a way to communicate the findings, the analysis is for not. This chapter not only covers the report writing process with examples, but also covers how to take detailed case notes. Although I have been writing reports for a while, there were still quite a few “ah ha” moments for me.

If you have any of his previous books, and are wondering if the new edition is worth the extra expense and time, I would say a resounding “Yes”. There is new content such as the Correlating Artifacts chapter and the Reports chapter. It has also been updated with some real life case examples that help drive home the points. If you’re new to Harlan’s series, I think this book is a great place to start. In addition to the newer operating systems, this book also covers XP, Sever 2003 and Vista.

It may also be a minor point, but I also like that fact that Harlan uses the pronoun “she” and not always “he” when talking about examiners.

I do have to say that Windows Forensics Analysis 2E is still one of my favorites, but that is probably because it was one of my first forensic books and has all my notes still in it :-)
"One Must Have" for Forensics Professionals - Windows Forensics Analysis Toolkit - by Harlan Carvey CISSP 31 octobre 2014
Par Dr. Larry Leibrock - Publié sur
Format: Broché Achat vérifié
I must state at the onset - This is a great digital forensics book.
This book as both an knowledge-builder and go-to desk-reference is a formidable and useful work.

It is very well written and well attributed. If i had to take one book about Windows 8 with me to Bezerkistan in order to complete an WIN 8 digital forensics mission. This Windows Forensics Analysis Tool Kit - is it.

I admire Harlan's technical forensics skills, understanding about limitations the forensics practice and his excellence in writing. This is a "must have" for digital forensics professionals. If you are in the digital forensics - business - get this book - read it - use it.
3 internautes sur 5 ont trouvé ce commentaire utile 
Great read for DFIR Pros 7 mai 2014
Par Daniel Garcia - Publié sur
Format: Broché Achat vérifié
While this book is an updated version of 3e (author mentions this) with some artifacts for win 8 it is still a great read. The last two chapters which focus on how to's and writing reports has been of great help and i plan to use the template to better organize my reporting format. Speaking of structures, i like that the book focuses on explaining the artifact structures, relevance and when you could use the tool applicable to parse the artifact. This also applies to the process methodology laid out in the book, i like the example of "why scan the machine twice with the same AV if it didn't find anything in the first place?" i have seen too many cases like this in real life. Also defining analysis goals before starting analysis is something i have been stressing on my self and my teammates and Harlan does a good job laying that out.

The concept of using micro timelines is great and i have found success applying this technique for finding pivot points rather than taking a kitchen sink approach and creating a supertimeline, not to say the supertimeline doesnt have its place :) it does but not all scenarios require one.

In closing, if you haven't picked up the 3e pick this one up, if you are new to digital forensics and incident response, pick this one up. having the textbook version helps as you can reference the material quicker and its easier on the eyes when it comes to screenshots and quoted text for ch.7 (timelines), i had a hard time reading these with the 3e ebook.
Excellent 10 septembre 2014
Par BB - Publié sur
Format: Broché Achat vérifié
Excellent book! This should be on every DFIR consultants bookshelf.
Ces commentaires ont-ils été utiles ? Dites-le-nous


Souhaitez-vous compléter ou améliorer les informations sur ce produit ? Ou faire modifier les images?