About

Chad Steel

Wiley Publishing, Inc.

Published by
Wiley Publishing, Inc.
10475 Crosspoint Boulevard
Indianapolis, IN 46256

http://www.wiley.com

2006 Chad Steel

Published by Wiley Publishing, Inc., Indianapolis, Indiana

Published simultaneously in Canada

13: 978-0-470-03862-8
ISBN-10:

0-470-03862-4

10 9 8 7 6 5 4 3 2 1

1MA/SQ/QU/QW/IN

No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning or otherwise , except as permitted under Sections 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, 222 Rosewood Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 646-8600. Requests to the Publisher for permission should be addressed to the Legal Department, Wiley Publishing, Inc., 10475 Crosspoint Blvd., Indianapolis, IN 46256, (317) 572-3447, fax (317) 572-4355, or online at http://www.wiley.com/go/permissions.

Limit of Liability/Disclaimer of Warranty: The publisher and the author make no representations or warranties with respect to the accuracy or completeness of the contents of this work and specifically disclaim all warranties, including without limitation warranties of fitness for a particular purpose. No warranty may be created or extended by sales or promotional materials. The advice and strategies contained herein may not be suitable for every situation. This work is sold with the understanding that the publisher is not engaged in rendering legal, accounting, or other professional services. If professional assistance is required, the services of a competent professional person should be sought. Neither the publisher nor the author shall be liable for damages arising here- from. The fact that an organization or Website is referred to in this work as a citation and/or a potential source of further information does not mean that the author or the publisher endorses the information the organization or Website may provide or recommendations it may make. Further, readers should be aware that Internet Websites listed in this work may have changed or disappeared between when this work was written and when it is read.

For general information on our other products and services or to obtain technical support, please contact our Customer Care Department within the U.S. at (800) 762-2974, outside the U.S. at (317) 572-3993 or fax (317) 572-4002.

Library of Congress Cataloging-in-Publication Data

Steel, Chad, 1975
Windows forensics: the field guide for conducting corporate computer investigations / Chad Steel.
p. cm.
Includes index.
ISBN-13: 978-0-470-03862-8 (pbk.)
ISBN-10: 0-470-03862-4 (pbk.)
1. Computer crimesInvestigationUnited StatesMethodology. 2. Microsoft Windows (Computer file) Security measures. 3. Computer networksSecurity measures. 4. InternetSecurity measures. 5. Computer security. I. Title.
HV8079.C65S84 2006
363.25 968dc22

2006005530

Trademarks: Wiley and the Wiley logo are trademarks or registered trademarks of John Wiley & Sons, Inc. and/or its affiliates , in the United States and other countries, and may not be used without written permission. Windows is a registered trademark of Microsoft Corporation in the United States and/or other countries . All other trademarks are the property of their respective owners . Wiley Publishing, Inc., is not associated with any product or vendor mentioned in this book.

Wiley also publishes its books in a variety of electronic formats. Some content that appears in print may not be available in electronic books.

To Laura. My search is over; love was right before my eyes.

About the Author

Chad Steel is a seasoned veteran with experience investigating more than 300 computer security incidents. Chad developed and taught the Computer Forensics graduate course in Penn State's engineering program as a member of the adjunct faculty and has taught both federal and local law enforcement, commercial clients , and graduate students in forensic analysis. He was the Head of IT Investigations for a Global 100 corporation and the Chief Security Officer and Managing Director, Systems Integration and Security Services, for a Fortune 100 consulting group .

Chad holds B.S. and M.S. degrees in Computer Engineering and is currently pursuing a Ph.D. at Virginia Tech. He can be reached at csteel@yahoo.com.

Credits

Executive Editor
Carol Long

Development Editor
Kelly D. Henthorne

Editorial Manager
Mary Beth Wakefield

Production Manager
Tim Tate

Vice President and Executive Group Publisher
Richard Swadley

Vice President and Executive Publisher
Joseph B. Wikert

Project Coordinator
Michael Kruzil

Graphics and Production Specialists
Jennifer Click
Carrie A. Foster
Brooke Graczyk
Stephanie D. Jumper
Barbara Moore
Lynsey Osborn

Quality Control Technicians
David Faust
Jessica Kramer
Brian H. Walls

Proofreading and Indexing
Techbooks

Acknowledgments

Getting a book from concept through to publication is a long road, and I would not have been able to complete the journey without the help of many folks along the way. I have some individual acknowledgments below but would like also to thank everyone who provided a tool, tip, or story that allowed me to complete this endeavor.

First, I would like to thank my wife, Laura, for her love and support in writing and editing this book. Without her, none of what I've accomplished would have been possiblethe book is just a small part of that.

There is a quantum leap between writing a book and actually getting it published. To that end, I'd like to thank my agent, William Brown of the Waterside Agency, for making the quickest sale for a first-time author (at least one who hasn't been featured on the evening news) in history.

One thing authors have going for them that other artists don't is an editor (no one "touches up" the works of a painter). I'd like to thank Kelly Henthorne for making me look like a better writer than I am. I'd also like to thank Carol Long and all of the staff at Wiley for giving me this opportunity.

Isaac Newton was quoted as saying, "If I have seen further it is by standing on the shoulders of Giants," which was itself borrowed as a phrase from earlier writers. For tools, I've made heavy use in this book of the excellent array of free software made available by Mark Russinovich and the folks at http://www.sysinternals.com. Likewise, the knowledge base that is http://www.Sourceforge.net and the community of people who support it helped to fill in gaps on some of the more technical areas of the book.

Finally, I'd like to thank my dogs, Foxxy and Charlie, for providing support in return for biscuits during the process. If you look closely, you can see that one of them made it into the book!



Windows Forensics. The Field Guide for Corporate Computer Investigations
Windows Forensics: The Field Guide for Corporate Computer Investigations
ISBN: 0470038624
EAN: 2147483647
Year: 2006
Pages: 71
Authors: Chad Steel

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net