Digital evidence can come from far more than a computer’s hard drive. In Learn Computer Forensics, investigator and technical trainer William Oettinger introduces the practices used to locate, preserve, examine, and report on information found across digital devices and systems. The focus is not just on tools: it is also on the careful process that makes an examination defensible and its findings understandable.
Follow the evidence from acquisition to analysis
The book moves from the planning and legal considerations of an investigation into evidence acquisition and computer-system fundamentals. Topics include chain of custody, forensic workstations, tool validation, write blocking, forensic imaging, hard-drive structures, and file systems. This progression helps readers see why reliable analysis starts with sound handling and documentation—not simply with searching for interesting files.
Read the traces left by computers
Its investigation chapters explore timeline and media analysis, deleted-data recovery, and Windows artifacts such as Registry information, browser history, shortcut files, Jump Lists, the Recycle Bin, prefetch data, and connected-device records. The contents also cover RAM analysis, email and internet artifacts, and ways to organize evidence into a clear forensic report.
Understand the responsibilities behind the work
Computer investigations may involve criminal matters or workplace and corporate concerns, and the book treats the process as more than a technical exercise. Case information, legal issues, evidence integrity, reporting, and expert-witness ethics all have a place in the material. That broader perspective helps connect individual artifacts to the investigation and the explanation of findings.
A structured introduction for aspiring examiners
Novice investigators and readers building a foundation in digital forensics will find a chapter-by-chapter route through the subject, with summaries, review questions, and further-reading sections. Prior familiarity with operating systems and file systems can be helpful, though the publisher notes it is not required. For readers who want to understand how digital evidence is acquired and examined with care, this is a practical place to begin.
User Reviews
Only logged in customers who have purchased this product may leave a review.
Original price was: $44.99.$22.50Current price is: $22.50.

There are no reviews yet.