O'Reilly logo

Windows Forensic Analysis Toolkit, 4th Edition by Harlan Carvey

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Index

Note: Page numbers followed by “f” and “b” refer to figures and boxes, respectively.

A

Acceptable use policies (AUPs), 254
Access control list (ACL), 127
Acme Consulting, 286, 288
ACMru key, 5, 151
Acquired images, 233–235
ASCII timelines, 212–213
Event Log file extraction, 87
historical Registry data, 152
installed AV applications, 186
malware detection, 182
multiple antivirus scans, 189–192
timeline analysis, 220, 247
timeline creation, 227
timeline creation on XP, 233–235
VSCs, 66b, 68b
batch files, 70
diskpart command, 64b
FTK Imager, 59f
image file formats, 73b
LiveView, 60b
overview, 59–73
ProDiscover, 71–73, 71f, 72f, 72f
ProDiscover BE, 66
VHD method, 61–65, 62f
VMDKs and SIFT, 68
VMWare method, 65–68, 67f
Acquisition process

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required