Online resource; title from PDF title page (SpringerLink, viewed March 16, 2016).
Summary
Harlan Carvey brings readers an advanced book on Windows Registry. The first book of its kind EVER -- Windows Registry Forensics provides the background of the Registry to help develop an understanding of the binary structure of Registry hive files. Approaches to live response and analysis are included, and tools and techniques for postmortem analysis are discussed at length. Tools and techniques will be presented that take the analyst beyond the current use of viewers and into real analysis of data contained in the Registry. Named a 2011 Best Digital Forens.
Contents
Registry analysis -- Processes and tools -- Analyzing the system hives -- Case studies: User hives -- RegRipper.