Book 10 of 14
Digital Forensics
Evidence acquisition, artifact analysis, memory forensics, timeline reconstruction, and cloud forensics
52
Chapters
10
Parts
4
Platforms
30+
Tools covered
Part 1 — Foundations
Part 2 — Windows Artifacts
- Ch 05NTFS and the MFT
- Ch 06Registry Forensics
- Ch 07Prefetch Analysis
- Ch 08Shimcache and Amcache
- Ch 09LNK Files and Jump Lists
- Ch 10Shellbags
- Ch 11Browser Artifacts
- Ch 12Email Artifacts
- Ch 13Windows Event Logs
- Ch 14BAM, DAM, and SRUM
- Ch 15Volume Shadow Copies
- Ch 16Windows Search Database
- Ch 17Deleted File Recovery and Carving
- Ch 18Anti-Forensics Detection
Part 3 — Memory Forensics
Part 4 — Disk Forensics
Part 5 — Network Forensics
Part 6 — Log Analysis
Part 7 — Timeline Analysis
Part 8 — Tooling
Part 9 — Linux, macOS & Cloud
Part 10 — Attribution