Windows Forensic Analysis Including DVD Toolkit

Windows Forensic Analysis Including DVD Toolkit
by Harlan Carvey

Windows Forensic Analysis Including DVD Toolkit
List Price: $59.95
Our Price: $47.22
You Save: $12.73 (21%)
Availability: Usually ships in 1-2 business days
Category: Book
See more book details and other editions


(Click here)
Buy this book at online book store in your country
Canada | UK | Germany | France

Book Summary Information

Author: Harlan Carvey
Technical Editor: Dave Kleiman
Edition: Paperback
Published: 2007-04-24
ISBN: 159749156X
Number of pages: 416
Publisher: Syngress

Book Reviews of Windows Forensic Analysis Including DVD Toolkit

Book Review: An excellent book for the IR practitioner
Summary: 5 Stars

I purchased this book a few days ago, and as soon as I read the first chapter, I realized that I needed to read the entire book as quickly as possible. This is a wonderful book, and parts of it truely invoked a state of "nerdvana" in me!

PRO's:

First, I will say that the information in this book is tightly packed. There is no unnecessary verbage, and the writing is direct, to the point and understandable. There is a high ratio of technical content to noise, and this greatly contributed to my enjoyment of the book. Even in the technical areas that I was already familiar with, I found the summary of the information to be precise, accurate and helpful. I can see keeping the book around as a reference guide for years to come. The general structure of the book, for example the sections in grey boxes with the [!] annotation, works well, and the end-of-chapter summary and review (particularly the Q&A) are good.

There were several sections, ones that I was personally weak in to start with, that I found particularly helpful, such as the sections on analyzing packed or compressed executables and malware. I had just never gotten around to reading the whitepapers on these, and I'm glad I didn't as those chapters of the book summarized in a few pages what would have taken many more to pick up by reading other original sources. I personally thought that the chapter-to-chapter flow of the narrative was fine for anyone who does incident response on a regular basis.

Through the years, Harlan Carvey has developed and made available his tools in an open (perl) format with no need for compensation. The tools on the DVD alone are worth the money of the book, and are a great addition to any IR toolkit. The references to third party tools, many of which I hadn't heard of, were also particularly helpful.

CON's:

If you are not very technical, or not very familiar with the Windows operating system, you may be overwhelmed by the level of technical detail. If you are an experienced administrator, however, you should be able to adapt what you know about other operating systems (e.g. file structures, process execution, etc.) fairly easily. There were a few typographical errors in the book that didn't detract from its readability or technical accuracy.

All in all, and excellent book, and a must-have for ANY windows incident responder.

Summary of Windows Forensic Analysis Including DVD Toolkit

The only book available on the market that addresses and discusses in-depth forensic analysis of Windows systems. Windows Forensic Analysis DVD Toolkit takes the reader to a whole new, undiscovered level of forensic analysis for Windows systems, providing unique information and resources not available anywhere else. This book covers both live and post-mortem response collection and analysis methodologies, addressing material that is applicable to law enforcement, the federal government, students, and consultants. This book also brings this material to the doorstep of system administrators, who are often the front line troops when an incident occurs, but due to staffing and budgets do not have the necessary knowledge to effectively respond. The companion DVD for the book contains significant, unique materials (movies, spreadsheet, code, etc.) not available any place else, as they were created by the author.

Encryption Books

Book Subjects
Most talked about in My book collaborations
Perl Scripting for Windows Security: Live Response, Forensic Analysis, and Monitoring ImagePerl Scripting for Windows Security: Live Response, Forensic Analysis, and Monitoring
by Harlan Carvey, Jeremy Faircloth
Elsevier Inc.; Published: 2007-12-28; Paperback; Book
Best price: $40.52
Price in other shops: $49.95
Rootkits for Dummies (For Dummies (Computer/Tech)) ImageRootkits for Dummies (For Dummies (Computer/ Tech))
by Larry Stevenson, Nancy Altholz
For Dummies; Published: 2007-01-30; Paperback; Book
Best price: $5.23
Price in other shops: $29.99
Enemy at the Water Cooler: Real-Life Stories of Insider Threats and Enterprise Security Management Countermeasures ImageEnemy at the Water Cooler: Real-Life Stories of Insider Threats and Enterprise Security Management Countermeasures
by Brian Contos
Syngress; Published: 2006-08-23; Paperback; Book
Best price: $25.94
Price in other shops: $49.95
How to Cheat at Windows System Administration Using Command Line Scripts (How to Cheat) ImageHow to Cheat at Windows System Administration Using Command Line Scripts (How to Cheat)
by Pawan K. Bhardwaj, Dave Kleiman, Brian Barber
Syngress; Published: 2006-09-15; Paperback; Book
Best price: $19.99
Price in other shops: $39.95
Security Log Management: Identifying Patterns in the Chaos ImageSecurity Log Management: Identifying Patterns in the Chaos
by Jacob Babbin, Dave Kleiman, Everett F. Carter Jr., Jeremy Faircloth, Mark Burnett, Esteban Gutierrez
Syngress; Published: 2006-01-13; Paperback; Book
Best price: $22.25
Price in other shops: $49.95
Microsoft Log Parser Toolkit ImageMicrosoft Log Parser Toolkit
by Gabriele Giuseppini, Mark Burnett, Jeremy Faircloth, Dave Kleiman
Syngress; Published: 2005-02-10; Paperback; Book
Best price: $21.84
Price in other shops: $39.95
Perfect Passwords: Selection, Protection, Authentication ImagePerfect Passwords: Selection, Protection, Authentication
by Mark Burnett
Syngress; Published: 2005-12-27; Paperback; Book
Best price: $10.00
Price in other shops: $24.95
CD and DVD Forensics ImageCD and DVD Forensics
by Paul Crowley
Syngress; Published: 2006-11-28; Paperback; Book
Best price: $31.50
Price in other shops: $49.95
Winternals Defragmentation, Recovery, and Administration Field Guide ImageWinternals Defragmentation, Recovery, and Administration Field Guide
by Dave Kleiman, Laura Hunter, Mahesh Satyanarayana, Kimon Andreoou, Nancy G Altholz
SYNGRESS; Published: 2006-05-12; Digital; Book
Best price: $19.98
Windows Forensic Analysis Including DVD Toolkit ImageWindows Forensic Analysis Including DVD Toolkit
by Harlan Carvey
Syngress; Published: 2007-04-24; Paperback; Book
Best price: $47.99
Price in other shops: $59.95
Similar Books and other products
Windows Forensics and Incident Recovery (The Addison-Wesley Microsoft Technology Series) ImageWindows Forensics and Incident Recovery (The Addison-Wesley Microsoft Technology Series)
by Harlan Carvey
Addison-Wesley Professional; Published: 2004-07-31; Paperback; Book
Best price: $29.88
Price in other shops: $59.99
Alternate Data Storage Forensics ImageAlternate Data Storage Forensics
by Amber Schroader, Tyler Cohen
Syngress Publishing; Published: 2007-05-15; Paperback; Book
Best price: $47.50
Price in other shops: $59.95
Virtual Honeypots: From Botnet Tracking to Intrusion Detection ImageVirtual Honeypots: From Botnet Tracking to Intrusion Detection
by Niels Provos, Thorsten Holz
Addison-Wesley Professional; Published: 2007-07-26; Paperback; Book
Best price: $28.92
Price in other shops: $49.99
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws ImageThe Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
by Dafydd Stuttard, Marcus Pinto
Wiley; Published: 2007-10-22; Paperback; Book
Best price: $26.91
Price in other shops: $50.00
Real Digital Forensics: Computer Security and Incident Response ImageReal Digital Forensics: Computer Security and Incident Response
by Keith J. Jones, Richard Bejtlich, Curtis W. Rose
Addison-Wesley Professional; Published: 2005-10-03; Paperback; Book
Best price: $32.60
Price in other shops: $59.99
Computer Forensics Library Boxed Set ImageComputer Forensics Library Boxed Set
by Keith J. Jones, Richard Bejtlich, Curtis W. Rose, Dan Farmer, Wietse Venema, Brian Carrier
Addison-Wesley Professional; Published: 2007-08-20; Hardcover; Book
Best price: $68.63
Price in other shops: $124.99
Windows Forensics: The Field Guide for Corporate Computer Investigations ImageWindows Forensics: The Field Guide for Corporate Computer Investigations
by Chad Steel
Wiley; Published: 2006-05-15; Paperback; Book
Best price: $17.26
Price in other shops: $39.99
EnCase Computer Forensics, includes DVD: The Official EnCE: EnCase Certified Examiner Study Guide ImageEnCase Computer Forensics, includes DVD: The Official EnCE: EnCase Certified Examiner Study Guide
by Steve Bunting
Sybex; Published: 2007-12-05; Paperback; Book
Best price: $36.35
Price in other shops: $69.99
File System Forensic Analysis ImageFile System Forensic Analysis
by Brian Carrier
Addison-Wesley Professional; Published: 2005-03-27; Paperback; Book
Best price: $35.10
Price in other shops: $59.99
Mastering Windows Network Forensics and Investigation (Mastering) ImageMastering Windows Network Forensics and Investigation (Mastering)
by Steven Anson, Steve Bunting
Sybex; Published: 2007-04-02; Paperback; Book
Best price: $18.30
Price in other shops: $59.99
Book store. Illustrated catalog of books on different categories