

4 Ͼ ſ û . ϰ Ǹ ذ ؼ ʼ 䱸ǰ ִ.
å ̷ ߿ ʰ Ǵ Ŀ ؼ ٷ ִ. 80% ü ߿ ִ. ϰ Ǹ ſ ߿ о̴.
å ϰ Ŀ ־ ýۿ Ź ϰ ϰ Ǿ. ̷кٴ ش Ź ο ش Ź ϴ, м Ͽ Ȱ ؼ ٷ. ڰ ͳݿ ҹ ٿ ? ý Կ ־ м ؼ ˾ƺ .
ٽ Ʈ ý ⺻ м, ڰ 츦 Կ ־ ýۿ Ǵ мϴ , ̳ й õ ִ ٷ, ƼƮ Ź Ȱ ƼƮ鿡 ؼ ٷ. ħػ о߿ Ǿ ִ Ĺ ؼ ٷ. Ŀ ־ ϴ , ȯ汸 , ٷ 忡 ռ 캻 ƼƮ мϱ ¼ҽ Ұ Բ ٷ.
å д ڵ Ͽ ⺻ ȴ. 100%Ϻ ߿ ٷ ֱ Ǹ ⺻ Ǹ Ѵ.
å 鼭 ñ e.encase@gmail.com ֱ ٶ.

01 Window Forensic 12
1.1 Registry 12
1.2 ý ⺻ 14
1.3 м 28
1.4 м 58
1.5 ƼƮ м 62
02 101
2.1 101
2.2 101
2.3 м 105
2.4 Volatility 111
2.5 Volatility Workbench 191
03 ¼ҽ 196
3.1 PCHunter 196
3.2 JumpListsView 200
3.3 Lnk Parser 202
3.4 Everything 204
10 3.5 NTFS Log Tracker 207
3.6 REGA 212
3.7 DCode 220
3.8 LastActivityView 222
3.9 UserAssistView 223
3.10 USBDeview 224
3.11 Thumbcache viewer 226
3.12 BrowsingHistoryView 228
3.13 Strings 234
3.14 dd 237
3.15 dumpIt 239
3.16 Autopsy 241
3.17 HxD 251
3.18 OTL 258
3.19 FTK imager 260
3.20 AnalyzerMFT 269