Windows Forensic Analysis Toolkit
Network Security · 2014
Now in its fourth edition – updated to cover Windows 8 – this classic work on Windows forensics has two major things in its favour: it is based on real-world experience; and it focuses on free or open-source tools. In fact, the majority of the tools – mostly written in Perl – and other material used in the book are available from its companion website.