메뉴 건너뛰기




Volumn 5, Issue , 2008, Pages

Forensic analysis of the Windows registry in memory

Author keywords

Cached data; Digital forensics; Microsoft Windows; Registry; Volatile memory

Indexed keywords

DIGITAL FORENSICS; DIGITAL STORAGE; ELECTRONIC CRIME COUNTERMEASURES; TREES (MATHEMATICS);

EID: 77955345007     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: None     Document Type: Conference Paper
Times cited : (34)

References (27)
  • 1
    • 84868579043 scopus 로고    scopus 로고
    • ReactOS, 〈http://www.reactos.org/en/index.html〉.
  • 3
    • 24344434657 scopus 로고    scopus 로고
    • The Windows Registry as a forensic resource
    • DOI 10.1016/j.diin.2005.07.003, PII S1742287605000587
    • Carvey H. The Windows registry as a forensic resource. Digital Investigation 2005a;2(3):201-5. (Pubitemid 41261446)
    • (2005) Digital Investigation , vol.2 , Issue.3 , pp. 201-205
    • Carvey, H.1
  • 4
    • 84868569310 scopus 로고    scopus 로고
    • Carvey H. Registry mining. 〈http://windowsir.blogspot.com/2005/01/ registry-mining.html〉, 2005b.
    • (2005) Registry Mining
    • Carvey, H.1
  • 5
    • 40749151022 scopus 로고    scopus 로고
    • Norwell, MA, US: Syngress, ISBN 159749156X
    • Carvey H. Windows forensic analysis. Norwell, MA, US: Syngress, ISBN 159749156X; 2007.
    • (2007) Windows Forensic Analysis
    • Carvey, H.1
  • 7
    • 34447559706 scopus 로고    scopus 로고
    • The VAD tree: A process-eye view of physical memory
    • DOI 10.1016/j.diin.2007.06.008, PII S1742287607000503
    • Dolan-Gavitt B. The VAD tree: a process-eye view of physical memory. Digital Investigation, http://dfrws.org/2007/proceedings/p62-dolan-gavitt.pdf, September 2007;4:62-4. (Pubitemid 47081448)
    • (2007) Digital Investigation , vol.4 , Issue.SUPPL. , pp. 62-64
    • Dolan-Gavitt, B.1
  • 11
    • 84868568731 scopus 로고    scopus 로고
    • Dolan-Gavitt B. SysKey and the SAM. 〈http://moyix.blogspot.com/2008/ 02/syskey-and-sam.html〉, 2008d.
    • (2008)
    • Dolan-Gavitt, B.1
  • 15
    • 84868575391 scopus 로고    scopus 로고
    • Macfarlane J. Parse:Win32Registry. 〈http://search.cpan.org/ jmacfarla/Parse-Win32Registry-0.30/〉.
    • MacFarlane, J.1
  • 16
    • 84868558256 scopus 로고    scopus 로고
    • Metasploit. Metasploit framework user guide. 〈http://www.metasploit. com/documents/users-guide.pdf〉, 2008.
    • (2008) Metasploit Framework User Guide
  • 18
    • 84868534479 scopus 로고    scopus 로고
    • National Institute of Standards and Technology (NIST). The CFReDS project. 〈http://www.cfreds.nist.gov/〉.
  • 21
    • 84868587275 scopus 로고    scopus 로고
    • Samba. Regfio library. 〈http://viewcvs.samba.org/cgi-bin/viewcvs. cgi/branches/SAMBA-4-0/source/lib/registry/〉.
  • 24
    • 84868560553 scopus 로고    scopus 로고
    • Stevens D. UserAssist. 〈http://blog.didierstevens.com/programs/ userassist/〉, 2006.
    • (2006)
    • Stevens, D.1
  • 25
    • 33751349368 scopus 로고    scopus 로고
    • FATKit: Detecting malicious library injection and upping the "anti"
    • July
    • Walters A. FATKit: detecting malicious library injection and upping the "anti", Technical report. 4TφResearch Laboratories; July 2006.
    • (2006) Technical Report. 4TφResearch Laboratories
    • Walters, A.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.