Windows Forensics And Incident Recovery
If you are responsible for Windows systems and you want your system to be secure you must expand your knowledge to various areas of computer security. Every system is a target and the only way to be prepared for an incident is to know what a perpetrator would change and where to look for evidence. This book promises to guide you into a part of computer security some consider to be exotic - forensics. Harlan Carvey is an instructor and course developer. He developed curriculum for a two-day, hands-on course addressing incident response and "live" forensics in the Windows environment. This course is extremely technical in nature and kept continually up to date. Harlan has presented at USENIX, DefCon9, Black Hat, GMU2003 on various topics specific to issues on Windows platforms, such as data hiding.