The second edition of this successful book shows how the contents of computer systems can be recovered for criminal evidence, even when hidden or subverted. Coverage includes Windows XP/2000 file systems, fast drives, new encryption technologies, and personal organisers.
From the reviews of the second edition:
"This book was the product of an 'arms race'. ? It is now listed as the standard text around which all the Forensic Computing courses at Cranfield and some other universities are based. ? It is filled with good practical advice and is especially good on interpreting partition tables. ? All in all this is a useful ? guide to the discipline. ? Truly the forensic computing expert is living in interesting times." (Alikelman, June, 2009)