Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
29 used & new from $42.44

Have one to sell? Sell yours here
 
   
Windows Forensic Analysis Including DVD Toolkit
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

Windows Forensic Analysis Including DVD Toolkit (Paperback)

by Harlan Carvey (Author), Dave Kleiman (Technical Editor)
Key Phrases: registry analysis, collecting volatile data, memory challenge, Live Response, File Analysis, Event Log (more...)
4.9 out of 5 stars See all reviews (14 customer reviews)

List Price: $59.95
Price: $53.95 & this item ships for FREE with Super Saver Shipping. Details
You Save: $6.00 (10%)
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Wednesday, July 15? Choose One-Day Shipping at checkout. Details
18 new from $49.78 11 used from $42.44
There is a newer edition of this item:
Windows Forensic Analysis DVD Toolkit, Second Edition Windows Forensic Analysis DVD Toolkit, Second Edition 5.0 out of 5 stars (8)
$62.95
In Stock.
What Do Customers Ultimately Buy After Viewing This Item?

Frequently Bought Together

Windows Forensic Analysis Including DVD Toolkit + File System Forensic Analysis + EnCase Computer Forensics, includes DVD: The Official EnCE: EnCase Certified Examiner Study Guide

Customers Who Bought This Item Also Bought

Mastering Windows Network Forensics and Investigation

Mastering Windows Network Forensics and Investigation

by Steven Anson
4.8 out of 5 stars (9)  $37.79
EnCase Computer Forensics, includes DVD: The Official EnCE: EnCase Certified Examiner Study Guide

EnCase Computer Forensics, includes DVD: The Official EnCE: EnCase Certified Examiner Study Guide

by Steve Bunting
4.1 out of 5 stars (18)  $44.09
Malware Forensics: Investigating and Analyzing Malicious Code

Malware Forensics: Investigating and Analyzing Malicious Code

by Cameron H. Malin
4.9 out of 5 stars (11)  $62.95
Computer Forensics Library Boxed Set

Computer Forensics Library Boxed Set

by Keith J. Jones
5.0 out of 5 stars (2)  $90.99
Windows Forensics: The Field Guide for Corporate Computer Investigations

Windows Forensics: The Field Guide for Corporate Computer Investigations

by Chad Steel
4.7 out of 5 stars (3)  $26.47
Explore similar items

Editorial Reviews

Product Description
The only book available on the market that addresses and discusses in-depth forensic analysis of Windows systems. Windows Forensic Analysis DVD Toolkit takes the reader to a whole new, undiscovered level of forensic analysis for Windows systems, providing unique information and resources not available anywhere else. This book covers both live and post-mortem response collection and analysis methodologies, addressing material that is applicable to law enforcement, the federal government, students, and consultants. This book also brings this material to the doorstep of system administrators, who are often the front line troops when an incident occurs, but due to staffing and budgets do not have the necessary knowledge to effectively respond. The companion DVD for the book contains significant, unique materials (movies, spreadsheet, code, etc.) not available any place else, as they were created by the author.

About the Author
Harlan Carvey developed an interest in computer security while in the military. After leaving active duty, he began working in the area of penetration testing and vulnerability assessments, leading teams of engineers, and developing his own tools to optimize his ability to collect and analyze data. As most clients employed Windows to some degree, Harlan began to see a disparity in knowledge and support for these operating systems, and decided to seize the opportunity and focus on Windows as an area of interest and research. This led him to address topics in incident response and forensic analysis, and to his position as a forensic analyst.
Harlan has been a prolific author and presenter, beginning with the Usenix LISA-NT conference in 2000. He has also presented at Black Hat, DefCon 9, MISTI, and HTCIA/GMU conferences. Harlan has had articles published in the Information Security Bulletin as well as on the SecurityFocus web site, and is the author of Windows Forensics and Incident Recovery.

Product Details

  • Paperback: 416 pages
  • Publisher: Syngress; Pap/DVD edition (April 24, 2007)
  • Language: English
  • ISBN-10: 159749156X
  • ISBN-13: 978-1597491563
  • Product Dimensions: 8.9 x 7 x 1.1 inches
  • Shipping Weight: 1.4 pounds (View shipping rates and policies)
  • Average Customer Review: 4.9 out of 5 stars See all reviews (14 customer reviews)
  • Amazon.com Sales Rank: #161,020 in Books (See Bestsellers in Books)

    Popular in these categories: (What's this?)

    #19 in  Books > Computers & Internet > Security & Encryption > Forensics
    #23 in  Books > Computers & Internet > Security & Encryption > Windows Security

Inside This Book (learn more)

Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

14 Reviews
5 star:
 (12)
4 star:
 (2)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.9 out of 5 stars (14 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
24 of 24 people found the following review helpful:
5.0 out of 5 stars Wow -- what a great forensics book -- a must read for investigators, July 5, 2007
I loved Windows Forensic Analysis (WFA). It's the first five star book from Syngress I've read since early 2006. WFA delivered just what I hoped to read in a book of its size and intended audience, and my expectations were high. If your job requires investigating compromised Windows hosts, you must read WFA.

Let me name three aspects of WFA that really sold me. First, the subject matter is exactly what I wanted to read. The book does not repeat basic or fundamental material you can (and should) read elsewhere, like working "crime scenes," hard drive image acquisition, and the like. I recommend the recent book Windows Forensics by Chad Steel (4 stars) as a great first book to read before WFA. The two are sufficiently different yet complementary to warrant reading both, in fact. In addition to not repeating material, WFA covers very recent (late 2006, early 2007) activity in Windows forensics that are not addressed by other books. The chapter on Windows memory analysis (ch 3) was even better than the Registry chapter that everyone likes. WFA cites plenty of outside sources in a way that doesn't confuse the reader and enriches the learning process.

Second, WFA introduces a vast number of tools to help investigators implement the concepts author Harlan Carvey explains. Many of the tools are Harlan's own work and are included on the book's DVD. The DVD even contains movies showing how to use some of the tools, like Harlan's Forensic Server Project. Many tools that were new to me appear in the book, but well-known commercial suites like EnCase do not. This is great; if you want to know EnCase, read the (3 star) book on it I reviewed last year. I intend to integrate many of these tools into my own CIRT's response processes.

Third, Harlan brings a lot of experience to WFA. He cites plenty of examples and niche topics that I haven't seen elsewhere. I had never heard of using multiple OLE streams to hide entire Word files in Excel spreadsheets and vice-versa. Better yet, Harlan describes how to find these techniques, along with other issues like alternate data streams. Many times multiple ways to approach a problem appear in WFA. Furthermore, Harlan continuously emphasizes implementing repeatable, automated processes to improve the accuracy and scalability of forensic investigations.

There really is no excuse to not read WFA. I think it would be interesting to try some of Harlan's tools and techniques on the images and evidence collected by myself and my Real Digital Forensics co-authors Keith Jones and Curtis Rose. Bravo to Harlan for writing WFA.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
9 of 9 people found the following review helpful:
5.0 out of 5 stars Not just for forensics, but for a deeper understanding of Windows itself., August 26, 2007
By Nikk Gilbert (Paris, France) - See all my reviews
I bought this book after reading Richard Bejtlichs review and can say I am not disappointed at all. Clearly this book is well worth the time and the money. After reading just half of the first chapter I was so engrossed I couldn't put the book down. I worked through the entire book, trying most of the tools, advice and experiments/labs that were included. The inclusion of the tools (on the included DVD) not only in Pearl but in .exe format was really a great touch. I'd consider this one of the best books written, not just for forensics but for a deeper understanding of Windows itself.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
12 of 13 people found the following review helpful:
4.0 out of 5 stars Book Review: Windows Forensic Analysis, June 11, 2007
By Andrew Hay "RHCE, Security+, GSEC, GCIA, GCIH... (Fredericton, New Brunswick, Canada) - See all my reviews
(REAL NAME)   
There are very few books on the topic of Windows Forensic Analysis and Harlan Carvey has taken it upon himself to provide the security community with a guided tour of the inner workings of Microsoft operating systems. As Microsoft does not yet offer a "forensic" track in it's training offerings most forensic knowledge of Windows comes from on the job experience or tool specific training offered by a vendor.

This book begins by leading you through the collection of evidence. The author provides you with examples of collecting data from live running systems using commercial tools, tools native to Windows, and advanced perl scripts which are provided on the accompanying DVD. Locard's Exchange Principle, a principle unknown to me prior to reading this book, is explained in great detail and is reference throughout the book. The concept is further demonstrated in an example using my favorite security tool, Netcat. People who respond to incidents need to know what to look for. Harlan dives deep into the key items of interest and explains how to pay special attention to volatile information such as system time, network connections, clipboard contents, and mapped drives, to name a few.

Once you have collected your data the author moves into specific chapters on how to analyze and make sense of it. Harlan does a fantastic job of explaining how to analyze memory (dumping the memory, analyzing crash dumps, reading through memory, etc.), analyzing the registry (tracking user activity, explaining how processes autostart from registry entries, etc.), analyzing windows files (working with event logs, common document formats, alternate data streams, etc.), analyzing executable files (static and dynamic analysis), and finally rootkits (detecting and preventing).

On the cover of the book the author has a quote by Troy Larson, Senior Forensic Investigator of Microsoft's IT Security Group which states:

"The Registry Analysis chapter alone is worth the price of the book."

When I first received the book I thought "Wow, that's a glowing recommendation" and upon reading the book cover to cover I couldn't agree more. I have yet to see a book which takes you through the intricacies of the Windows Registry in such a way that I, being a Linux person, could easily relate to.

The rootkit chapter was a little light on content but the rest of the book makes up for it. There are books out there dedicated to rootkits and I wouldn't expect the author to provide a book that explains everything about everything and still expect people to be able to carry it with them.

The accompanying DVD contains the scripts mentioned in the book, some videos explaining the use of some tools, as well as a bonus folder that contains ... well I'll let you buy the book to find out what cool tools are provided.

This book should be on every analysts shelf whether they perform Windows forensic analysis as part of their role, or think that they might be called upon to do so in a pinch. I also think that this book is a fantastic supplement to any Microsoft training and any security training you may receive in the future.

I give this book 4.5 stars as it is easy to read and kept my interest throughout the entire book.

Do yourself a favor and pick up this book today.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars Great Book
This book is well written and a great asset to anyone doing computer investigations and forensics.
Published 1 month ago by Lannes J. Hilboldt

4.0 out of 5 stars Just like the title says.
It's a must for starting forensic analysis, especially on live systems. Maybee you can find the same information unorganised in forums, but time is money so spend it wisely.
Published 3 months ago by S. Fiset

5.0 out of 5 stars Excellent Real World Forensic Reference


This Book is great for beginners in the field of Forensics or veteran Forensic specialists in the field. Read more
Published 3 months ago by Paul M. Chavez

5.0 out of 5 stars An excellent book for the IR practitioner
I purchased this book a few days ago, and as soon as I read the first chapter, I realized that I needed to read the entire book as quickly as possible. Read more
Published 14 months ago by Mark Lachniet

5.0 out of 5 stars Invaluable in a case
Harlan Carvey's book, Windows Forensic Analyisis, is an invaluable resource in any computer forensic examination of a Windows based computer. Read more
Published 16 months ago by Anthony Balzanto

5.0 out of 5 stars Taking Windows Analysis to the Next Step...
Harlan poured his clear love of incident response and of the forensic profession into this book. Windows Forensic Analysis dives into many exceptional topics that are routinely... Read more
Published 16 months ago by R. Lee

5.0 out of 5 stars A must have for the forensic professional
Once again Harlan Carvey has provided a resource worth every penny. The chapters detailing registry and memory analysis alone were extremely valuable to me. Read more
Published 19 months ago by J. Fichera, CCE

5.0 out of 5 stars Unique and helpful
This book is essential for understanding how to analyze memory dumps, albeit many forensic investigators will usually turnoff a computer instead of getting a memory capture to do... Read more
Published 21 months ago by Robert Hudock

5.0 out of 5 stars This is a Must Read before it goes on your reference shelf
Often times when you read reviews of technical books the reviewers will say, 'This book deserves a place on your reference shelf. Read more
Published 21 months ago by S. Wesner

5.0 out of 5 stars Excellent Book
A well written, easy to read must have for anyone who works in the field of computer forensics.
Published 22 months ago by S. J. Wolf

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]


Active discussions in related forums
  Discussion Replies Latest Post
Does anyone use Discovering Geometry: An Investigative Approach? 4 18 hours ago
Textbooks for Kindle DX? 38 20 hours ago
   


Product Information from the Amapedia Community

Beta (What's this?)


So You'd Like to...


Look for Similar Items by Category


Bath Wonders from LUSH

LUSH bath bombs
Find bath bombs, bath melts, shower jellies, and more great gifts for yourself (or a friend!) from LUSH Fresh Handmade Cosmetics.

Shop LUSH now

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Buy Three Books, Get a Fourth Free

4-for-3 Books
Order any four eligible books under $10 and get the lowest-price book free in our 4-for-3 Books Store. See more details.
 

Best Books

Best of the Month
See our editors' picks and more of the best new books on our Best of the Month page.
 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Paranoia
Paranoia by Joseph Finder
My Soul to Lose
My Soul to Lose by Rachel Vincent
Glenn Beck's Common Sense
Glenn Beck's Common Sense

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates