Digital Forensics · 2014
Windows Registry Forensics with Volatility Framework | Kapil Soni
3rd Edition
Windows Registry Forensics with Volatility Framework is a hands-on guide to one of the richest evidence sources on any Windows system. It covers the structure of the registry, the artifacts that matter in an investigation, and how to extract them both from disk and from memory images using the Volatility Framework. Written for investigators who want repeatable technique over theory, it turns the registry into a reliable timeline of user and system activity.
What you'll learn
- How the Windows Registry is structured and where evidence hides
- Key registry artifacts for user activity, execution, and persistence
- Recovering registry data from memory images with Volatility
- Building an investigative timeline from registry artifacts
Who it's for
Digital forensics analysts, incident responders, and students of memory and Windows forensics.