Copyright
Acquiring Editor:Chris Katsaropoulos
Editorial Project Manager:Benjamin Rearick
Project Manager:Punithavathy Govindaradjane
Designer:Matthew Limbert
Syngress is an imprint of Elsevier
225 Wyman Street, Waltham, MA 02451, USA
Copyright 2014 Elsevier Inc. All rights reserved.
No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or any information storage and retrieval system, without permission in writing from the publisher. Details on how to seek permission, further information about the Publishers permissions policies and our arrangements with organizations such as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our website: www.elsevier.com/permissions.
This book and the individual contributions contained in it are protected under copyright by the Publisher (other than as may be noted herein).
Notices
Knowledge and best practice in this field are constantly changing. As new research and experience broaden our understanding, changes in research methods or professional practices, may become necessary. Practitioners and researchers must always rely on their own experience and knowledge in evaluating and using any information or methods described herein. In using such information or methods they should be mindful of their own safety and the safety of others, including parties for whom they have a professional responsibility.
To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume any liability for any injury and/or damage to persons or property as a matter of products liability, negligence or otherwise, or from any use or operation of any methods, products, instructions, or ideas contained in the material herein.
Library of Congress Cataloging-in-Publication Data
Shavers, Brett.
X-Ways Forensics practitioners guide / Brett Shavers, Eric Zimmerman. pages cm
Includes bibliographical references and index.
ISBN 978-0-12-411605-4 (alk. paper)
1.X-Ways Forensics (Computer program) 2.Forensic sciences. 3.Criminal investigations.I. Zimmerman, Eric, 1974- II. Title.
HV8073.S4228 2014
363.25028553dc23
2013022602
British Library Cataloguing-in-Publication Data
A catalogue record for this book is available from the British Library
ISBN: 978-0-12-411605-4
Printed and bound in the United States of America
14 15 16 17 18 10 9 8 7 6 5 4 3 2 1
For information on all Syngress publications, visit our website at store.elsevier.com/Syngress
Acknowledgments
Eric Zimmerman and Jimmy Weg are two forensic examiners that are true X-Ways Forensics practitioners. I am humbled to have their efforts attributed to this book, as both Eric and Jimmy are two of the most competent forensic examiners around. After Eric agreed to coauthor the Practitioners Guide to X-Ways, I knew this would be the go-to guide for all current and new users of X-Ways Forensics. To have Jimmy Weg as the Tech Editor only solidified this books credibility. Eric and Jimmy, thank you for your support in this endeavor.
Stefan Fleischmann of X-Ways Software Technology has been a constant support of my personal use of X-Ways Forensics since the forensic version was first released. Little did I know that by asking Stefan in 2004 to teach an X-Ways Forensics class in Seattle (the first class in the USA) that I would be introduced to the best forensic utility available, with amazing support, both personal and professional, from Stefan. Additionally, Stefans support of this book has been a tremendous help in ensuring the information is up to date and accurate.
I also thank Craig Ball for his kind words for the foreword of this book. I first met Craig Ball in the first X-Ways class and, since then, have followed his witty and intelligent writings on forensics and electronic discovery. Craig has an amazing command presence and superb knowledge of the law surrounding electronic discovery and forensics (he is an attorney), but he is also an advocate and longtime user of X-Ways Forensics.
As for my number one supporter, I thank my wife Chikae, as she not only listened to my endless jabbering of all things digital forensics at home but has also supported me in this second book even before I finished writing my first book. When looking at the success of our children, or even my personal success, I look no further than to my wife and I know how it is all possible.
Brett Shavers
I would like to start by saying thank you to all of the dedicated men and women in both law enforcement and private industry that go to work every day and tirelessly pursue the truth in the realm of digital forensics. While we may at times have different missions, the goal is the same: to tell the story of what happened as it relates to a computer. It is my belief that X-Ways Forensics can help you tell that story in an efficient and succinct manner.
I want to extend a special thanks to Brett and Jimmy, my coauthor and tech editor. I am grateful for being given the opportunity to write this book and work closely with you over the past few months. Your passion for X-Ways Forensics comes through in every chapter.
I too want to thank Stefan Fleishmann and all the X-Ways employees for putting together such a fantastic and capable tool. Your dedication to making the best software available has made more impact in the world than you know.
Finally, I would like to thank my wife Michele for supporting me when it came time to add writing a book to my already crazy schedule. Thank you for being a constant source of encouragement. You are a fantastic wife and mother. Wesley and I are blessed to have you.
Eric Zimmerman
About the Authors
Brett Shavers is a former law enforcement officer of a municipal police department and has been an investigator assigned to state and federal task forces. Besides working many specialty positions, Brett was the first digital forensics examiner at his police department, attended over 1000 hours of digital forensic training courses across the country, collected more than a few certifications along the way, and set up his departments first digital forensics lab in a small, cluttered storage closet.
Brett has been an adjunct instructor at the University of Washingtons Digital Forensics Program, an expert witness and digital forensics consultant, a prolific speaker at conferences, and a blogger on digital forensics and is an honorary member of the Computer Technology Investigators Network. Brett has worked cases ranging from child pornography investigations as a law enforcement investigator to a wide range of civil litigation cases as a digital forensics expert consultant. This is Bretts second book, with Placing the Suspect Behind the Keyboard, being his first.