-
1
-
-
84868579043
-
-
ReactOS, 〈http://www.reactos.org/en/index.html〉.
-
-
-
-
3
-
-
24344434657
-
The Windows Registry as a forensic resource
-
DOI 10.1016/j.diin.2005.07.003, PII S1742287605000587
-
Carvey H. The Windows registry as a forensic resource. Digital Investigation 2005a;2(3):201-5. (Pubitemid 41261446)
-
(2005)
Digital Investigation
, vol.2
, Issue.3
, pp. 201-205
-
-
Carvey, H.1
-
4
-
-
84868569310
-
-
Carvey H. Registry mining. 〈http://windowsir.blogspot.com/2005/01/ registry-mining.html〉, 2005b.
-
(2005)
Registry Mining
-
-
Carvey, H.1
-
5
-
-
40749151022
-
-
Norwell, MA, US: Syngress, ISBN 159749156X
-
Carvey H. Windows forensic analysis. Norwell, MA, US: Syngress, ISBN 159749156X; 2007.
-
(2007)
Windows Forensic Analysis
-
-
Carvey, H.1
-
7
-
-
34447559706
-
The VAD tree: A process-eye view of physical memory
-
DOI 10.1016/j.diin.2007.06.008, PII S1742287607000503
-
Dolan-Gavitt B. The VAD tree: a process-eye view of physical memory. Digital Investigation, http://dfrws.org/2007/proceedings/p62-dolan-gavitt.pdf, September 2007;4:62-4. (Pubitemid 47081448)
-
(2007)
Digital Investigation
, vol.4
, Issue.SUPPL.
, pp. 62-64
-
-
Dolan-Gavitt, B.1
-
11
-
-
84868568731
-
-
Dolan-Gavitt B. SysKey and the SAM. 〈http://moyix.blogspot.com/2008/ 02/syskey-and-sam.html〉, 2008d.
-
(2008)
-
-
Dolan-Gavitt, B.1
-
15
-
-
84868575391
-
-
Macfarlane J. Parse:Win32Registry. 〈http://search.cpan.org/ jmacfarla/Parse-Win32Registry-0.30/〉.
-
-
-
MacFarlane, J.1
-
16
-
-
84868558256
-
-
Metasploit. Metasploit framework user guide. 〈http://www.metasploit. com/documents/users-guide.pdf〉, 2008.
-
(2008)
Metasploit Framework User Guide
-
-
-
18
-
-
84868534479
-
-
National Institute of Standards and Technology (NIST). The CFReDS project. 〈http://www.cfreds.nist.gov/〉.
-
-
-
-
19
-
-
84991799247
-
An architecture for specification-based detection of semantic integrity violations in kernel dynamic data
-
Berkeley, CA, USA: USENIX Association
-
Petroni Jr NL, Fraser T, Walters A, Arbaugh WA. An architecture for specification-based detection of semantic integrity violations in kernel dynamic data. In: USENIXSS' 06: Proceedings of the 15th Conference on USENIX Security Symposium. Berkeley, CA, USA: USENIX Association; 2006. p. 20.
-
(2006)
USENIXSS' 06: Proceedings of the 15th Conference on USENIX Security Symposium
, pp. 20
-
-
Petroni Jr., N.L.1
Fraser, T.2
Walters, A.3
Arbaugh, W.A.4
-
20
-
-
33745167170
-
Microsoft Windows internals
-
Fourth edition, Redmond, WA, USA: Microsoft Press, ISBN 0735619174
-
Russinovich ME, Solomon DA. Microsoft Windows internals, Fourth edition: Microsoft Windows Server(TM) 2003, Windows XP, and Windows 2000 (pro-developer). Redmond, WA, USA: Microsoft Press, ISBN 0735619174; 2004.
-
(2004)
Microsoft Windows Server(TM) 2003, Windows XP, and Windows 2000 (Pro-developer)
-
-
Russinovich, M.E.1
Solomon, D.A.2
-
21
-
-
84868587275
-
-
Samba. Regfio library. 〈http://viewcvs.samba.org/cgi-bin/viewcvs. cgi/branches/SAMBA-4-0/source/lib/registry/〉.
-
-
-
-
24
-
-
84868560553
-
-
Stevens D. UserAssist. 〈http://blog.didierstevens.com/programs/ userassist/〉, 2006.
-
(2006)
-
-
Stevens, D.1
-
25
-
-
33751349368
-
FATKit: Detecting malicious library injection and upping the "anti"
-
July
-
Walters A. FATKit: detecting malicious library injection and upping the "anti", Technical report. 4TφResearch Laboratories; July 2006.
-
(2006)
Technical Report. 4TφResearch Laboratories
-
-
Walters, A.1
|