or
Sign in to turn on 1-Click ordering
Sell Us Your Item
For a $2.00 Gift Card
Trade in
Kindle Edition
Read instantly on your iPad, PC, Mac, Android tablet or Kindle Fire
Buy Price: $51.35
Rent From: $14.15
 
 
 
More Buying Choices
Have one to sell? Sell yours here
Sorry, this item is not available in
Image not available for
Color:
Image not available

To view this video download Flash Player

 

Windows Forensic Analysis DVD Toolkit, Second Edition [Paperback]

Harlan Carvey
5.0 out of 5 stars  See all reviews (18 customer reviews)

Buy New
$54.58 & FREE Shipping. Details
Rent
$20.40
Only 20 left in stock (more on the way).
Ships from and sold by Amazon.com. Gift-wrap available.
In Stock.
Rented by RentU and Fulfilled by Amazon.
Want it Friday, June 21? Choose One-Day Shipping at checkout. Details
Free Two-Day Shipping for College Students with Amazon Student

Formats

Amazon Price New from Used from
Kindle Edition
Rent from
$51.35
$14.15
 
Paperback $54.58  
Unknown Binding --  
Rent Your Textbooks
Save up to 70% when you rent your textbooks on Amazon. Keep your textbook rentals for a semester and rental return shipping is free.
There is a newer edition of this item:
Windows Forensic Analysis Toolkit, Third Edition: Advanced Analysis Techniques for Windows 7 Windows Forensic Analysis Toolkit, Third Edition: Advanced Analysis Techniques for Windows 7 4.9 out of 5 stars (7)
$54.49
In Stock.

Book Description

June 11, 2009 1597494224 978-1597494229 2

"If your job requires investigating compromised Windows hosts, you must read Windows Forensic Analysis." -Richard Bejtlich, Coauthor of Real Digital Forensics and Amazon.com Top 500 Book Reviewer

"The Registry Analysis chapter alone is worth the price of the book." -Troy Larson, Senior Forensic Investigator of Microsoft's IT Security Group "I also found that the entire book could have been written on just registry forensics. However, in order to create broad appeal, the registry section was probably shortened. You can tell Harlan has a lot more to tell." -Rob Lee, Instructor and Fellow at the SANS Technology Institute, coauthor of Know Your Enemy: Learning About Security Threats, 2E

Author Harlan Carvey has brought his best-selling book up-to-date to give you: the responder, examiner, or analyst the must-have tool kit for your job. Windows is the largest operating system on desktops and servers worldwide, which mean more intrusions, malware infections, and cybercrime happen on these systems. Windows Forensic Analysis DVD Toolkit, 2E covers both live and post-mortem response collection and analysis methodologies, addressing material that is applicable to law enforcement, the federal government, students, and consultants. The book is also accessible to system administrators, who are often the frontline when an incident occurs, but due to staffing and budget constraints do not have the necessary knowledge to respond effectively. The book's companion DVD contains significant new and updated materials (movies, spreadsheet, code, etc.) not available any place else, because they are created and maintained by the author.

  • Best-Selling Windows Digital Forensic book completely updated in this 2nd Edition
  • Learn how to Analyze Data During Live and Post-Mortem Investigations
  • DVD Includes Custom Tools, Updated Code, Movies, and Spreadsheets!

Frequently Bought Together

Windows Forensic Analysis DVD Toolkit, Second Edition + Windows Forensic Analysis Toolkit, Third Edition: Advanced Analysis Techniques for Windows 7 + Digital Forensics with Open Source Tools
Price for all three: $158.76

Buy the selected items together


Editorial Reviews

Review

"If your job requires investigating compromised Windows hosts, you must read Windows Forensic Analysis."--Richard Bejtlich, Coauthor of Real Digital Forensics and Amazon.com Top 500 Book Reviewer

About the Author

Harlan Carvey (CISSP) is a Vice President of Advanced Security Projects with Terremark Worldwide, Inc. Terremark is a leading global provider of IT infrastructure and "cloud computing” services, based in Miami, FL. Harlan is a key contributor to the Engagement Services practice, providing disk forensics analysis, consulting, and training services to both internal and external customers. Harlan has provided forensic analysis services for the hospitality industry, financial institutions, as well as federal government and law enforcement agencies. Harlan's primary areas of interest include research and development of novel analysis solutions, with a focus on Windows platforms.
Harlan holds a bachelor's degree in electrical engineering from the Virginia Military Institute and a master's degree in the same discipline from the Naval Postgraduate School. Harlan resides in Northern Virginia with his family.


Product Details

  • Paperback: 512 pages
  • Publisher: Syngress; 2 edition (June 11, 2009)
  • Language: English
  • ISBN-10: 1597494224
  • ISBN-13: 978-1597494229
  • Product Dimensions: 7.5 x 1.2 x 9.2 inches
  • Shipping Weight: 2 pounds (View shipping rates and policies)
  • Average Customer Review: 5.0 out of 5 stars  See all reviews (18 customer reviews)
  • Amazon Best Sellers Rank: #436,929 in Books (See Top 100 in Books)

More About the Author

Harlan Carvey's interest in computer and information security began while he was an officer in the U.S. military, and a student at the Naval Postgraduate School, earning his MSEE. After leaving military service, he began working in the field of commercial and government information security consulting, performing vulnerability assessments and penetration tests. While employed at one company, he was the sole developer of a program for collecting security-specific information (i.e., Registry entries, file information, configuration settings, etc.) from Windows NT systems during vulnerability assessments. The purpose of the product was to overcome shortfalls in commercial scanning products and provide more valuable information to the customer. Harlan has also done considerable work in the area of incident response and forensics, performing internal and external investigations. He has also written a number of proof-of-concept tools for educating users in such topics as Windows null sessions, file signature analysis, and the retrieval of metadata from a variety of file formats. Harlan's experience with computers began in the early '80s, with a Timex-Sinclair 1000. Around that time, he was learning to program BASIC on an Apple IIe. From there, he moved on to computers such as the Epson QX-10 and the TRS-80, on which he programmed BASIC and learned some rudimentary PASCAL, using the TurboPASCAL compiler. Since then, he's worked with SunOS and Solaris systems, as well as various versions of DOS and Windows, OS/2, and Linux. Harlan has presented at a variety of computer security conferences, including Usenix, DefCon9, Black Hat, GMU2003/HTCIA/RCFG, WACCI, and PFIC2010. He has discussed various topics specific to issues on Windows platforms, such as data hiding, incident response, and forensic analysis. He has had articles published in the Information Security Bulletin, on the SecurityFocus web site, and in the Hakin9 magazine. Finally, Harlan has written a number of open source programs (including RegRipper), which have been made available online and via CDs/DVDs in his books.

Customer Reviews

5.0 out of 5 stars
(18)
5.0 out of 5 stars
4 star
0
3 star
0
2 star
0
1 star
0
Time after time I read the questions being asked and went to the book. hogfly  |  11 reviewers made a similar statement
Harlan brings together this area of his book with a discussion of analyzing the data. Jimmy Weg  |  5 reviewers made a similar statement
Most Helpful Customer Reviews
17 of 18 people found the following review helpful
5.0 out of 5 stars Essential reading June 7, 2009
Format:Paperback|Amazon Verified Purchase
The second edition of Harlan's book nicely complements the first and is essential reading for practitioners at all levels. For those of us who primarily engage in exams of acquired images, the chapters on Registry Analysis, File Analysis, Executable Analysis, and Rootkit Detection provide and build upon basic concepts that go beyond what is taught in beginning and intermediate computer forensics courses.

The registry analysis chapter is particularly valuable and one that I draw on repeatedly. The accompanying DVD, with its scripts, not only provides tools to gather the data that Harlan describes, but provides a means to learn while you read by taking a hands on approach to registry analysis.

The chapter on file analysis teaches fundamentals of system files and logs that can provide key evidence in an exam. It explains not only what may be found, but how to get it and why it got there. These are the types of issues that can aid immeasurably when it comes to report writing and courtroom testimony. Similarly, the discussions on malware, rootkits, and executables provide guidance and solutions to considerations of whether an uninvited influence played a role in data arriving on, or departing from, a system.

For those who don't engage in incident or live response at the moment, the time is fast approaching when that aspect forensics is going to be vital to us all. Harlan explains what information is available, and he describes the methods and tools with which we can acquire volatile data and access information that's gone once the plug is pulled. Harlan brings together this area of his book with a discussion of analyzing the data.
... Read more ›
Was this review helpful to you?
15 of 18 people found the following review helpful
5.0 out of 5 stars Even better than the first edition June 21, 2009
By hogfly
Format:Paperback
In ancient times, when philosophers and scientists gathered to discuss and debate important topics, people would travel for weeks and months to arrive, just to hear the debates. To listen to the great minds of the time, to learn from them, and on occasion ask questions. In 2009 that trend continues though in a different fashion.

In the case of Windows Forensic Analysis we are fortunate enough to have Harlan Carvey. He has a deep well of knowledge to pull from and he continues to pull buckets of information out of the well to keep us all well hydrated. I was honored to read this book, and it's my privilege to write a review. It's the least I could do.

It's a text book, it's a field manual, it's reference material. This is Windows Forensic Analysis Second Edition and it's the best damn book on the planet for Windows Forensics. I thought I liked the first edition and then I read the second.

It's been updated to be sure, but it's also been expanded. There's current information contained in the over 400 pages of content. There are case studies, there are details you won't find elsewhere.

Want to know how to dump memory and collect volatile data? It's in the book.
Can't recall which tool has certain limitations or what the tool can do? It's in the book.
Want to know how to analyze volatile data? It's in the book.
Want to learn how to registry works? It's in the book.
Want to know how to do Windows Forensic Analysis? Read this book.

I've watched the forums and mailing lists since the first edition of the book was released two years ago. Time after time I read the questions being asked and went to the book. In an overwhelming majority of cases, the answer was there. To those of you that asked these questions, do yourself a favor.
... Read more ›
Was this review helpful to you?
6 of 6 people found the following review helpful
Format:Paperback
For several years, Harlan Carvey has led the field in sharing and publishing his extensive knowledge of Windows forensics. The latest edition of Harlan's book does not disappoint, and this updated and revised copy remains THE Windows forensics reference book to have on your shelf. Harlan draws on both his in-depth knowledge of the Windows operating system and his extensive experience in real-world incident response to successfully bridge what is often a gap between the world of the first responder and the world of the forensic analyst. This is particularly appropriate at a time when those roles continue to converge. If there is information to be found on a Windows system (and I think Harlan knows and has documented the Windows registry better than anyone at Microsoft), Harlan will tell you not only where, but also how to find it. But he doesn't stop there; Harlan also provides several open-source (Perl-based) tools on the accompanying DVD to allow you to extract a variety of useful data from a Windows computer to aid you in your investigation. If you want to do two things to aid your incident response / forensics capabilities, then 1. buy this book, and 2. learn Perl!
Comment | 
Was this review helpful to you?
7 of 8 people found the following review helpful
5.0 out of 5 stars There is no substitute for this book September 7, 2009
Format:Paperback
I read and reviewed the 1st Ed of this book in July 2007, and I just finished reading Windows Forensic Analysis 2nd Ed (WFA2E) this weekend. If your job involves investigating Windows systems, you must read this book. It's as simple as that. There is no substitute for this book. It also perfectly complements other solid forensics works already published.

The three main reasons why I liked the 1st Ed hold for the 2nd Ed. The subject matter is exactly what I wanted to read. WFA2E introduces a vast number of tools to help investigators implement the concepts explained by the author. Harlan brings a lot of experience to WFA. Of these three, I really appreciate Harlan's experience. He is constantly "in the fight" so he knows what works and what doesn't. He's been around so long that he knows what he's talking about. If he encounters a problem, he can either try fixing it himself or he is friends with someone who can work the issue. All of these characteristics shine in WFA2E.

I expect to see a 3rd Ed of this book in a few years, incorporating more Windows Vista and Windows 7 material. It might also be helpful to consider techniques for Windows Server and Mobile platforms in the 3rd Ed. Regardless, I will look forward to that book when it arrives because I enjoyed WFA1E and WFA2E so much.
Comment | 
Was this review helpful to you?
Most Recent Customer Reviews
5.0 out of 5 stars computer book
This book was a gift for my computer "guru" son, who requested it as a birthday present. I have no clue what it's all about, but he is definitely pleased with it.
Published 16 months ago by grammie
5.0 out of 5 stars Must have resource for Digital Forensics/Incident Response
I had read WFA 2/e a while back and just kept forgetting to post a review.

One caveat though.... Read more
Published 21 months ago by Joseph Garcia
5.0 out of 5 stars Unbelievable book. A true reference in Forensic Analysis
It's very hard say other word about this book than... excepcional. The reading it's very nice because the author knows what are explaining, gives very good (and real) examples... Read more
Published 21 months ago by Alexandre Borges
5.0 out of 5 stars Incredible Book!
I'm extremely impressed with how thoroughly the author covers the methods discussed in this book. Usually when I pick up a book like this I'm prepared for more questions than when... Read more
Published on September 7, 2010 by Allen W.
5.0 out of 5 stars Skibo
I saw this book at Barnes and Noble and picked it up and started to scan it, To my Demised it caught my curiosity. The more I read the more I could relate! This book is top rated! Read more
Published on May 7, 2010 by TnT
5.0 out of 5 stars The best forensic book currently available
I've started reading or read a number of forensic books in the past two years. Though I have yet to read a specific Operating System forensic book, most have generally focused on... Read more
Published on September 1, 2009 by Jesse G. Lands
5.0 out of 5 stars Excellent text covers live response and traditional computer forensics
Harlan Carvey is one of the most prolific writers on compute forensics. He has a spare writing style that conveys information directly, without excursions. Read more
Published on August 29, 2009 by Jerry Saperstein
5.0 out of 5 stars Required Reading
As practicing investigators, we have seen the tide shift over the last few years - from a concentration on traditional disk acquisition and file analysis to a multifaceted practice... Read more
Published on August 24, 2009 by Colin C. Sheppard
5.0 out of 5 stars Must have book for IR/CFE's
This is a book that anyone in the Incident Response or Computer Forensic arena HAS to have on their bookshelf. Read more
Published on August 6, 2009 by T. Yarrish
5.0 out of 5 stars Possession of this Book is Required for All Examiners
Why this book? Because there are no others like it.

Harlan has taken the topics from the first 3 chapters and given examiners not only the information of `how to', but... Read more
Published on June 18, 2009 by Brett Shavers
Search Customer Reviews
Only search this product's reviews


Forums

Topic From this Discussion
DVD included in kindle edition?
That's what i would like to know before i buy. I dont' want to have to buy the normal book to get the DVD :(
Apr 16, 2011 by TC |  See all 6 posts
Have something you'd like to share about this product?
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Search Customer Discussions
Search all Amazon discussions


So You'd Like to...


Create a guide


Look for Similar Items by Category