Windows Registry Forensics,
Edition 1 Advanced Digital Forensic Analysis of the Windows RegistryEditors: By Harlan Carvey
Conformance
-
PDF/UA-1
-
The publication contains a conformance statement that it meets the EPUB Accessibility 1.1, WCAG 2.1, Level AA standard. Please see https://bornaccessible.benetech.org/certified-publishers/ for further details of our compatibility testing.
-
The publication was certified on 20250625
-
Accessibility addendum
-
The certifier's credential is https://bornaccessible.benetech.org/certified-publishers/
-
For detailed accessibility information, see Elsevier’s website at https://www.elsevier.com/about/accessibility
-
Compatibility tested
-
For queries regarding accessibility information, contact [email protected]
Ways Of Reading
-
This e-publication is accessible to the full extent that the file format and types of content allow, on a specific reading device, by default, without necessarily including any additions such as textual descriptions of images or enhanced navigation.
-
All contents of the digital publication necessary to use and understanding, including any text, images (via alternative descriptions), video (via audio description) is fully accessible via suitable audio reproduction.
Navigation
-
The contents of the PDF have been tagged to permit access by assistive technologies as per PDF-UA-1 standard.
-
Page breaks included from the original print source
Additional Accessibility Information
-
All (or substantially all) textual matter is arranged in a single logical reading order (including text that is visually presented as separate from the main text flow, e.g., in boxouts, captions, tables, footnotes, endnotes, citations, etc.). Non-textual content is also linked from within this logical reading order. (Purely decorative non-text content can be ignored).
-
The language of the text has been specified (e.g., via the HTML or XML lang attribute) to optimise text-to-speech (and other alternative renderings), both at the whole document level and, where appropriate, for individual words, phrases or passages in a different language.
-
For readers with color vision deficiency, use of color (e.g., in diagrams, graphics and charts, in prompts, or on buttons inviting a response) is not the sole means of graphical distinction or of conveying information
-
Content is enhanced with ARIA roles to optimize organization and facilitate navigation
-
Where interactive content is included in the product, controls are provided (e.g., for speed, pause and resume, reset) and labelled to make their use clear.
Note
-
This product relies on 3rd party tooling which may impact the accessibility features visible in inspection copies. All accessibility features mentioned would be present in the purchased version of the title.
Description
Windows Registry Forensics provides the background of the Windows Registry to help develop an understanding of the binary structure of Registry hive files. Approaches to live response and analysis are included, and tools and techniques for postmortem analysis are discussed at length. Tools and techniques are presented that take the student and analyst beyond the current use of viewers and into real analysis of data contained in the Registry, demonstrating the forensic value of the Registry.
Named a 2011 Best Digital Forensics Book by InfoSec Reviews, this book is packed with real-world examples using freely available open source tools. It also includes case studies and a CD containing code and author-created tools discussed in the book.
This book will appeal to computer forensic and incident response professionals, including federal government and commercial/private sector contractors, consultants, etc.
Key Features
- Named a 2011 Best Digital Forensics Book by InfoSec Reviews
- Packed with real-world examples using freely available open source tools
- Deep explanation and understanding of the Windows Registry – the most difficult part of Windows to analyze forensically
- Includes a CD containing code and author-created tools discussed in the book
About the author
By Harlan Carvey, DFIR analyst, presenter, and open-source tool author
Chapter 1 Registry Analysis
Introduction
What is "Registry Analysis"?
What is the Windows Registry?
Registry Structure
Summary
Frequently Asked Questions
References
Chapter 2 Tools
Introduction
Live Analysis
Summary
Frequently Asked Questions
References
Chapter 3 Case Studies: The System
Introduction
Security and SAM hives
System Hive
Software Hive
BCD Hive
Summary
Frequently Asked Questions
References
Chapter 4 Case Studies: Tracking User Activity
Introduction
Tracking User Activity
Scenarios
Summary
References
Windows Forensic Analysis DVD Toolkit, 2e 9781597494229, $69.95, 5/2009, Syngress BOOKSCAN: 2704
File System Forensic Analysis, 9780321268174, $64.99, Pearson, 3/2005, Bookscan: 8958
Real Digital Forensics, 9780321240699, $59.99, Pearson, 9/2004, Bookscan: 5399