ENGLISH

Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7

Book information

Publisher
Syngress
Year
2012
ISBN
1597497274, 9781597497275
Language
english
Format
PDF
Filesize
8 MB (8714775 bytes)
Edition
Pages
296\294
Time added
2021-03-09 13:40:07

Description

Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and postmortem response collection and analysis methodologies for Windows 7. It considers the core investigative and analysis concepts that are critical to the work of professionals within the digital forensic analysis community, as well as the need for immediate response once an incident has been identified. Organized into eight chapters, the book discusses Volume Shadow Copies (VSCs) in the context of digital forensics and explains how analysts can access the wealth of information available in VSCs without interacting with the live system or purchasing expensive solutions. It also describes files and data structures that are new to Windows 7 (or Vista), Windows Registry Forensics, how the presence of malware within an image acquired from a Windows system can be detected, the idea of timeline analysis as applied to digital forensic analysis, and concepts and techniques that are often associated with dynamic malware analysis. Also included are several tools written in the Perl scripting language, accompanied by Windows executables. This book will prove useful to digital forensic analysts, incident responders, law enforcement officers, students, researchers, system administrators, hobbyists, or anyone with an interest in digital forensic analysis of Windows 7 systems. Timely 3e of a Syngress digital forensic bestsellerUpdated to cover Windows 7 systems, the newest Windows versionNew online companion website houses checklists, cheat sheets, free tools, and demos Front Cover Windows Forensic Analysis Toolkit Copyright Page Contents Preface Intended Audience Organization of this Book Chapter 1: Analysis Concepts Chapter 2: Immediate Response Chapter 3: Volume Shadow Copies Chapter 4: File Analysis Chapter 5: Registry Analysis Chapter 6: Malware Detection Chapter 7: Timeline Analysis Chapter 8: Application Analysis Online Content Acknowledgments About the Author About the Technical Editor 1 Analysis Concepts Introduction Analysis Concepts Windows Versions Analysis Principles Goals Tools Versus Processes Locard’s Exchange Principle Avoiding Speculation Direct and Indirect Artifacts Least Frequency of Occurrence Documentation Convergence Virtualization Setting up an Analysis System Summary 2 Immediate Response Introduction Being Prepared to Respond Questions The Importance of Preparation Logs Data Collection Training Summary 3 Volume Shadow Copies Introduction What Are “Volume Shadow Copies”? Registry Keys Live Systems ProDiscover F-Response Acquired Images VHD Method VMWare Method Automating VSC Access ProDiscover Summary Reference 4 File Analysis Introduction MFT File System Tunneling Event Logs Windows Event Log Recycle Bin Prefetch Files Scheduled Tasks Jump Lists Hibernation Files Application Files Antivirus Logs Skype Apple Products Image Files Summary References 5 Registry Analysis Introduction Registry Analysis Registry Nomenclature The Registry as a Log File USB Device Analysis System Hive Services Software Hive Application Analysis NetworkList NetworkCards Scheduled Tasks User Hives WordWheelQuery Shellbags MUICache UserAssist Virtual PC TypedPaths Additional Sources RegIdleBackup Volume Shadow Copies Virtualization Memory Tools Summary References 6 Malware Detection Introduction Malware Characteristics Initial Infection Vector Propagation Mechanism Persistence Mechanism Artifacts Detecting Malware Log Analysis Dr. Watson Logs Antivirus Scans AV Write-ups Digging Deeper Packed Files Digital Signatures Windows File Protection Alternate Data Streams PE File Compile Times MBR Infectors Registry Analysis Internet Activity Additional Detection Mechanisms Seeded Sites Summary References 7 Timeline Analysis Introduction Timelines Data Sources Time Formats Concepts Benefits Format Time Source System User Description TLN Format Creating Timelines File System Metadata Event Logs Windows XP Windows 7 Prefetch Files Registry Data Additional Sources Parsing Events into a Timeline Thoughts on Visualization Case Study Summary 8 Application Analysis Introduction Log Files Dynamic Analysis Network Captures Application Memory Analysis Summary References Index

Similar books