|
This chapter introduced you to the details of forensic analysis of a Microsoft Windows system. You should pay particular attention to the Registry and the forensic data you can extract from it. Also important to your forensic investigation is the index.dat file. These two are the most important items to learn in this chapter.
Additional topics in this chapter, such as examining the swap file and extracting data from a live system, are also important to any forensic examination of a Windows computer. However, they may not yield quite as much information as examining index.dat and the Registry. You were also introduced to basic memory forensics and tools such as Volatility.
|