Comprehensive forensic reference explaining how file systems function and how forensic tools might work on particular file systems
File System Forensics delivers comprehensive knowledge of how file systems function and, more importantly, how digital forensic tools might function in relation to specific file systems. It provides a step-by-step approach for file content and metadata recovery to allow the reader to manually recreate and validate results from file system forensic tools.
The book includes a supporting website that shares all of the data (i.e. sample file systems) used for demonstration in the text and provides teaching resources such as instructor guides, extra material, and more.
Written by a highly qualified associate professor and consultant in the field, File System Forensics includes information on:
- The necessary concepts required to understand file system forensics for anyone with basic computing experience
- File systems specific to Windows, Linux, and macOS, with coverage of FAT, ExFAT, and NTFS
- Advanced topics such as deleted file recovery, fragmented file recovery, searching for particular files, links, checkpoints, snapshots, and RAID
- Issues facing file system forensics today and various issues that might evolve in the field in the coming years
File System Forensics is an essential, up-to-date reference on the subject for graduate and senior undergraduate students in digital forensics, as well as digital forensic analysts and other law enforcement professionals.
Pay easily by card, Klarna, Apple Pay or Google Pay. Not happy? You always have a 14-day money-back guarantee. Read more in our terms. If you have any questions, email us at hello@memmo.org.
Memmo makes studying easier – wherever you are in the world. We bring your course books and smart study tools together in one place: summaries, quizzes, podcasts and flashcards. Plus Ted, your study buddy who answers anything you wonder. Over 75,000 students already study here – built to help you learn faster and stress less.