Investigating Windows Systems
Harlan Carvey · Academic Press (Elsevier) · First edition · 2018
Identifier: ISBN 978-0-12-811415-5
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
Case-driven walkthroughs of Windows examinations where the narration is the analyst's thought process: what question is being asked, which artifact is chosen next, and why a hypothesis was dropped. Deliberately excludes the artifact reference material from the author's other books.
Who it is for, and when
The right book for an examiner who knows the artifacts but produces unfocused examinations. It models scoping a question, deciding when you have enough, and writing the result down. Pairs with Windows Forensic Analysis Toolkit and Windows Registry Forensics, which supply the artifact detail this book assumes you have.
What it does not cover
Not an artifact reference and not a tool manual — it will not tell you where an artifact lives. Images and scenarios are Windows 7/10-era, so the specific parsers shown are dated even though the reasoning transfers.
Go to the source
Open at shop.elsevier.com (opens in a new tab)https://shop.elsevier.com/books/investigating-windows-systems/carvey/978-0-12-811415-5
Details
- Type
- Book
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Author
- Harlan Carvey
- Publisher
- Academic Press (Elsevier)
- Version verified
- First edition
- Year
- 2018
- Identifier
- ISBN 978-0-12-811415-5
- Topics
- windows, case-studies, triage, reporting, foundations
- Checked at source
Related entries
Autopsy
FreeAn open-source graphical forensic platform built over The Sleuth Kit, with an ingest-module architecture for keyword search, hash matching, web and email artefacts, and timeline review. It is now maintained by Sleuth Kit Labs, which also sells the commercial Cyber Triage product.
X-Ways Forensics
PaidA commercial Windows forensic examination environment from the German publisher X-Ways Software Technology AG, built on their WinHex disk editor and known for running from a portable installation with very low overhead. Licences are perpetual and protected by a local or network dongle, or by a bring-your-own-device arrangement.
A large collection of free single-purpose Windows artefact parsers — among them MFTECmd, PECmd, LECmd, JLECmd, AmcacheParser, SBECmd, EvtxECmd, RECmd, and the Timeline Explorer and Registry Explorer GUIs. The tools are still distributed from ericzimmerman.github.io, with a Get-ZimmermanTools helper that pulls the current set.
The long-established Forensic Toolkit, originally AccessData's and now owned and sold by Exterro, which acquired the product line. It covers processing of computer and mobile data, distributed indexing and keyword search, artefact analysis, timeline visualisation, and Mac file system examination.
A community-maintained, machine-readable knowledge base of digital forensic artefact definitions — where an artefact lives and how to collect it — expressed in YAML and licensed Apache-2.0. It is documented at artifacts.readthedocs.io and coordinated through the forensicartifacts Google Group and the Open Source DFIR Slack.