Rating:  Summary: Too much incorrect information Review: Too much technical information is incorrect. This book never made it past the editing process, and the exercises were never checked.The information regarding digital signatures is incorrect. Much of the information regarding partitions is incorrect. The information in regards to boot structures and MACS is scant, and what is there has been copied from existing web pages. Only enough information on NT and the MFT to confuse and confound. The exercises are hard to follow, and even suggest using a different operating system if they do not work. The examiner cannot switch the operating system on the drive being examined - this is ridiculous. The book is written with the primary audience of law enforcement. If a law enforcement officer were to have this book as their only education in computer forensics, their testimony would never stand up. I truly doubt that the material covered is sufficient to allow one to pass the IACIS certification. A competent forensic examiner would not use this book other than as a reference for using DriveSpy.
|