'Accelerated Windows Malware Analysis' by Dmitry Vostokov delivers an authoritative, methodical framework for digital evidence acquisition, forensic examination, and cybercrime investigation. Emphasizing legal admissibility, forensic soundess, and rigorous chain of custody, this volume covers the full lifecycle of a digital investigation.
Key topics include physical disk imaging, file system analysis (NTFS, EXT4), Windows artifact examination (Registry, Prefetch, Event Logs), volatile RAM memory capture and analysis, network packet dissection, browser history extraction, and forensic report writing. Workflows utilizing Autopsy, FTK Imager, and EnCase are detailed.
An indispensable handbook for digital forensic examiners, incident response specialists, corporate investigators, and law enforcement analysts.
Contents at a Glance
Chapter 1: Windows Operating System Architecture and Kernel Components
Chapter 2: Windows Authentication: Kerberos, NTLM, and LSASS Internals
Chapter 3: Active Directory Domain Services and Group Policy Objects
Chapter 4: Windows Security Event Logs and Sysmon Monitoring
Chapter 5: Privilege Management and Access Control Lists (DACLs/SACLs)
Chapter 6: PowerShell for Security Testing and Administration
Chapter 7: Common Windows Vulnerabilities and Lateral Movement
Chapter 8: Hardening Windows Workstations and Domain Controllers
Index & Further Reading