TY - BOOK AU - Robinson, Michael K. TI - Digital forensics workbook SN - 9781517713607 U1 - 614.10285 PY - 2015///] 2015. ©2015 CY - North Charleston, South Carolina : PB - CreateSpace, KW - Computer crimes -- Investigation N1 - Includes index; Software write blocking -- Creating forensic images -- File system identification -- Mounting forensic images for scanning -- Recovering files from forensic images -- Artifacts in the registry -- Hashing -- File signature analysis -- File analysis -- Internet history -- E-mail header analysis -- Prefetch files -- Shortcuts/links (.lnk) files and jump lists -- Thumbnail caches -- GREP searches -- File carving -- Timestamps and timelines -- Recovering passwords -- Mounting images as virtual machines -- Memory acquisition and analysis -- Network traffic -- Mobile apps and data N2 - The Digital Forensics Workbook is a filled with over 60 hands-on activities using over 40 different tools for digital forensic examiners who want to gain practice acquiring and analyzing digital data. Topics include analysis of media, network traffic, memory, and mobile apps. By becoming proficient in these activities, examiners can then focus on the recovered data and conduct in-depth analyses. This workbook was designed to augment existing digital forensics learning, whether it be formalized academic courses, industry training classes, on-the-job learning, or independent studying. The hands-on activities include step-by-step procedures for the reader so they obtain the identical results presented in the workbook. Activities include over 150 questions and answers to reinforce content. Additional exercises with answers are also provided so readers can apply what they have learned ER -