Guide to Computer Forensics and Investigations
Amelia Phillips, Bill Nelson, Christopher Steuart · Course Technology (Cengage) · 2024
Identifier: ISBN 978-0-357-67288-4
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
The long-running course textbook for digital forensics programmes: lab setup and policy, acquisition, operating-system and email and mobile artifacts, report writing and expert-witness basics, with end-of-chapter exercises. Written to be taught from, not read at the bench.
Who it is for, and when
The most useful entry point for someone with no prior exposure who needs a map of the whole field in one pass, and the standard assigned text if you are building or taking a course. Also the cheapest way for a lawyer or manager to learn what an examination actually involves end to end.
What it does not cover
Textbook breadth means textbook depth — it will not get you through a hard NTFS, memory or mobile problem, and its tool walkthroughs are tied to specific vendor product versions that change faster than the book. Cengage's own product page was not reachable for verification, so confirm the edition statement and check for a newer edition before assigning it.
Go to the source
Open at openlibrary.org (opens in a new tab)https://openlibrary.org/isbn/9780357672884
Details
- Type
- Book
- Written for
- New to the fieldWorking examinerNew to the field, Working examiner
- Author
- Amelia Phillips, Bill Nelson, Christopher Steuart
- Publisher
- Course Technology (Cengage)
- Year
- 2024
- Identifier
- ISBN 978-0-357-67288-4
- Topics
- foundations, evidence-handling, reporting, expert-testimony, imaging
- Checked at source
Related entries
An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.
A single-author treatment of digital evidence that puts investigative reasoning and admissibility ahead of tooling, then works through Windows, Unix, Macintosh, mobile and network evidence sources. Roughly half the book is about how to reason from evidence to a defensible conclusion and how that conclusion survives a courtroom.
A book about the attribution gap: how you get from "this account or this machine did it" to "this person did it", using physical investigation, surveillance, interviews and case timelines alongside the forensic artifacts.
A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.
Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.