EnCase Computer Forensics: The Official EnCE Study Guide, 2nd Edition

EnCase Computer Forensics: The Official EnCE Study Guide, 2nd Edition

Authored by Steve Bunting
Certification 1 views 0 downloads 2012
Published 2012
Language English
Publisher Sybex (Wiley)
'EnCase Computer Forensics - The Official EnCE-EnCase Certified Examiner Study Guide - 2nd Edition' delivers an authoritative, methodical framework for digital evidence acquisition, forensic examination, and cybercrime investigation. Emphasizing legal admissibility, forensic soundess, and rigorous chain of custody, this volume covers the full lifecycle of a digital investigation.

Key topics include physical disk imaging, file system analysis (NTFS, EXT4), Windows artifact examination (Registry, Prefetch, Event Logs), volatile RAM memory capture and analysis, network packet dissection, browser history extraction, and forensic report writing. Workflows utilizing Autopsy, FTK Imager, and EnCase are detailed.

An indispensable handbook for digital forensic examiners, incident response specialists, corporate investigators, and law enforcement analysts.
Contents at a Glance
Chapter 1: Digital Forensics Principles and Chain of Custody
Chapter 2: Evidence Acquisition: Disk Imaging, E01, and Raw DD Formats
Chapter 3: File System Analysis: NTFS, FAT32, exFAT, and EXT4
Chapter 4: Forensic Toolkits: Autopsy, FTK Imager, and EnCase Workflows
Chapter 5: Windows Artifact Analysis: Registry, Prefetch, Shimcache, and Shellbags
Chapter 6: Browser Forensics: History, Cookies, Cache, and Downloads
Chapter 7: Memory Forensics: RAM Capture and Volatility Framework Analysis
Chapter 8: Timeline Analysis, Correlation, and Forensic Report Writing
Index & Further Reading