Fundamental Computer Investigation Guide For Windows



User avatar


Posts: 4270

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Mon Jan 29, 2007 1:33 am

Fundamental Computer Investigation Guide For Windows

Fundamental Computer Investigation Guide For Windows

Here's a handy little guide on forensics in Windows environments just recently produced MS. Below is the intro to the online guide:

Internet connectivity and technological advances expose computers and computer networks to criminal activities such as unauthorized intrusion, financial fraud, and identity and intellectual property theft. Computers can be used to launch attacks against computer networks and destroy data. E-mail can be used to harass people, transmit sexually explicit images, and conduct other malicious activities. Such activities expose organizations to ethical, legal, and financial risks and often require them to conduct internal computer investigations.

This guide discusses processes and tools for use in internal computer investigations. It introduces a multi-phase model that is based on well-accepted procedures in the computer investigation community. It also presents an applied scenario example of an internal investigation in an environment that includes Microsoft® Windows®–based computers. The investigation uses Windows Sysinternals tools (advanced utilities that can be used to examine Windows–based computers) as well commonly available Windows commands and tools.

Some of the policies and procedures invoked in investigations that result from computer security incidents might also exist in disaster recovery plans. Although such plans are beyond the scope of this guide, it is important for organizations to establish procedures that can be used in emergency and disaster situations. Organizations should also identify and manage security risks wherever possible.

You can also download the entire guide HERE.

Let us know what you think,


User avatar


Posts: 237

Joined: Thu Jul 20, 2006 8:58 am

Location: HOA

Post Tue Jan 30, 2007 1:10 pm

Re: Fundamental Computer Investigation Guide For Windows

I actually like this guide. Its really brief, so it allows for someone new to IT security to read this doc in roughly an hour and get the basics down.

Return to Forensics

Who is online

Users browsing this forum: No registered users and 1 guest

Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software