Legal Cyber Academy
BookPaidCurrent

Investigating Windows Systems

Harlan Carvey · Academic Press (Elsevier) · First edition · 2018

Identifier: ISBN 978-0-12-811415-5

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

Case-driven walkthroughs of Windows examinations where the narration is the analyst's thought process: what question is being asked, which artifact is chosen next, and why a hypothesis was dropped. Deliberately excludes the artifact reference material from the author's other books.

Who it is for, and when

The right book for an examiner who knows the artifacts but produces unfocused examinations. It models scoping a question, deciding when you have enough, and writing the result down. Pairs with Windows Forensic Analysis Toolkit and Windows Registry Forensics, which supply the artifact detail this book assumes you have.

What it does not cover

Not an artifact reference and not a tool manual — it will not tell you where an artifact lives. Images and scenarios are Windows 7/10-era, so the specific parsers shown are dated even though the reasoning transfers.

Go to the source

Open at shop.elsevier.com (opens in a new tab)

https://shop.elsevier.com/books/investigating-windows-systems/carvey/978-0-12-811415-5

Details

Type
Book
Written for
New to the fieldWorking examinerNew to the field, Working examiner
Author
Harlan Carvey
Publisher
Academic Press (Elsevier)
Version verified
First edition
Year
2018
Identifier
ISBN 978-0-12-811415-5
Topics
windows, case-studies, triage, reporting, foundations
Checked at source
  • An open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.

  • A commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.

  • A large collection of free single-purpose Windows artefact parsers — among them MFTECmd, PECmd, LECmd, JLECmd, AmcacheParser, SBECmd, EvtxECmd, RECmd, and the Timeline Explorer and Registry Explorer GUIs. The tools are still distributed from ericzimmerman.github.io, with a Get-ZimmermanTools helper that pulls the current set.

  • The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.

  • A community-maintained, machine-readable knowledge base of digital forensic artefact definitions — where an artefact lives and how to collect it — expressed in YAML and licensed Apache-2.0. It is documented at artifacts.readthedocs.io and coordinated through the forensicartifacts Google Group and the Open Source DFIR Slack.