Appendix appB. Case Study

Introduction

In this appendix, we will use an infected machine to illustrate how to conduct primary analysis on different types of evidence, and we will go through live analysis along with the post-mortem analysis.

Get Practical Windows Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.