As long as networks of Microsoft Windows systems are managed,
administered, and used by people, security incidents will occur. Windows
systems are highly pervasive throughout the entire computing infrastructure,
from home and school systems, to high-end e-commerce sites. In contrast to
this pervasiveness, information regarding conducting effective incident
response and forensic audit activities on Windows systems is limited. While
there are many security books available, none focus specifically on Windows
security. There are also resources available online, but they are scattered and
often too general. This book is a compilation of all the information currently
available on this subject. It is for anyone who manages or administers Windows
systems (including home users) and needs to know how to react when they
suspect that an incident has occurred. It guides the reader through
information, tools, and techniques that are required to conduct incident
response or a live forensics audit activities. By providing the necessary
background for understanding how incidents occur and how data can be
hidden on compromised systems, the reader will have a better understanding of
the "whys" and "hows" of incident response and forensic audit activities. *It is
important to note that regulatory issues are also pushing organizations toward
better security and incident preparedness policies.