Talk With an Expert

Computer Forensics: Introduction to Incident Response and Investigation of Windows NT/2000

Computer Forensics: Introduction to Incident Response and Investigation of Windows NT/2000 (PDF, 1.63MB)Published: 04 Dec, 2001
Created by
Norman Haase

The purpose of this paper is to be an introduction to computer forensics. Computer forensics is a newly emerged and developing field which can be described as the study of digital evidence resulting from an incident. It involves collection and analysis of digital data within an investigative process. Other important steps include incident preparation, detection and recovery. All these procedures should be documented and conducted according to a standard methodology (Mandia and Prosise, 2001; McMillan, 2000). After introducing some important incident response considerations I will focus on a strategies for dealing with compromised Windows NT/2000. My hope is that this paper might be of some assistance in handling your own incidents and investigations. This paper is about investigating Windows hosts and conducting an analysis in order to promote growth and learning as opposed to a 'how-to' guide to gather legal evidence in view of criminal prosecution.