Extracting windows registry information from physical memory
暂无分享,去创建一个
[1] Mark Russinovich,et al. Windows® Internals: Including Windows Server 2008 and Windows Vista, Fifth Edition , 2009 .
[2] Timothy D. Morgan. Recovering deleted data from the Windows registry , 2008 .
[3] Lianhai Wang,et al. Windows Memory Analysis Based on KPCR , 2009, 2009 Fifth International Conference on Information Assurance and Security.
[4] Mourad Debbabi,et al. Extraction of forensically sensitive information from windows physical memory , 2009, Digit. Investig..
[5] Brendan Dolan-Gavitt,et al. Forensic analysis of the Windows registry in memory , 2008, Digit. Investig..
[6] Tianjie Cao,et al. Collecting Sensitive Information from Windows Physical Memory , 2009, J. Comput..
[7] Hong Ding,et al. Carving the Windows Registry Files Based on the Internal Structure , 2009, 2009 First International Conference on Information Science and Engineering.
[8] Harlan Carvey. The Windows Registry as a forensic resource , 2005, Digit. Investig..
[9] Lianhai Wang,et al. Exploratory study on memory analysis of Windows 7 operating system , 2010, 2010 3rd International Conference on Advanced Computer Theory and Engineering(ICACTE).