Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Arrow up icon
GO TO TOP
Windows Forensics Cookbook

You're reading from   Windows Forensics Cookbook Over 60 practical recipes to acquire memory data and analyze systems with the latest Windows forensic tools

Arrow left icon
Product type Paperback
Published in Aug 2017
Publisher
ISBN-13 9781784390495
Length 274 pages
Edition 1st Edition
Concepts
Arrow right icon
Authors (2):
Arrow left icon
 de Courcier de Courcier
Author Profile Icon de Courcier
de Courcier
Oleg Skulkin Oleg Skulkin
Author Profile Icon Oleg Skulkin
Oleg Skulkin
Arrow right icon
View More author details
Toc

Table of Contents (19) Chapters Close

Title Page
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Customer Feedback
Preface
1. Digital Forensics and Evidence Acquisition FREE CHAPTER 2. Windows Memory Acquisition and Analysis 3. Windows Drive Acquisition 4. Windows File System Analysis 5. Windows Shadow Copies Analysis 6. Windows Registry Analysis 7. Main Windows Operating System Artifacts 8. Web Browser Forensics 9. Email and Instant Messaging Forensics 10. Windows 10 Forensics 11. Data Visualization 12. Troubleshooting in Windows Forensic Analysis

Google Chrome analysis with Magnet AXIOM


Google Chrome is another very popular web browser. You will find its artifacts during many forensic examinations, not only on Windows systems, but also macOS, Linux, and even mobile platforms. With the help of this recipe you will learn how to parse Google Chrome artifacts with Magnet AXIOM.

Getting ready

Of course, you can use the whole forensic image as the source, but it is much faster to extract the Google Chrome folder from the user's profile, as this greatly reduces the dataset that has to be parsed. Here is where you can find the folders you need:

Windows XP:

C:\Documents and Settings\%USERNAME%\Local Settings\Application Data\Google\Chrome

Windows Vista and above:

C:\Users\%USERNAME%\AppData\Local\Google\Chrome

Export the folder, make sure Magnet AXIOM with a valid licence or trial is installed on your forensic workstation, and you are ready to go.

How to do it...

Create a new case in AXIOM, use the folder you exported as the evidence source, and make...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at £13.99/month. Cancel anytime
Visually different images