{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T18:31:41Z","timestamp":1761676301050,"version":"3.40.3"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319201245"},{"type":"electronic","value":"9783319201252"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-20125-2_13","type":"book-chapter","created":{"date-parts":[[2015,6,26]],"date-time":"2015-06-26T14:22:20Z","timestamp":1435328540000},"page":"145-162","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Introducing and Analysis of the Windows 8 Event Log for Forensic Purposes"],"prefix":"10.1007","author":[{"given":"Javad","family":"Talebi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ramlan","family":"Mahmoud","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,6,27]]},"reference":[{"key":"13_CR1","unstructured":"Sharma, H., Sabharwal, N.: Investigating the implications of virtual forensics. In: 2012 International Conference on Advances in Engineering, Science and Management (ICAESM), pp. 617\u2013620. IEEE (2012)"},{"key":"13_CR2","unstructured":"Gupta, S.: Windows Logon Forensics. SANS Institute InfoSec Reading Room. https:\/\/www.sans.org\/reading-room\/whitepapers\/forensics\/windows-logon-forensics-34132"},{"issue":"2","key":"13_CR3","first-page":"77","volume":"2","author":"F Daryabar","year":"2013","unstructured":"Daryabar, F., Dehghantanha, A., Udzir, N.I.: A review on impacts of cloud computing on digital forensics. Int. J. Cyber-Secur. Digit. Forensics (IJCSDF) 2(2), 77\u201394 (2013)","journal-title":"Int. J. Cyber-Secur. Digit. Forensics (IJCSDF)"},{"issue":"4","key":"13_CR4","first-page":"311","volume":"1","author":"A Aminnezhad","year":"2012","unstructured":"Aminnezhad, A., Dehghantanha, A., Abdullah, M.: A survey on privacy issues in digital forensics. Int. J. Cyber-Secur. Digit. Forensics (IJCSDF) 1(4), 311\u2013323 (2012)","journal-title":"Int. J. Cyber-Secur. Digit. Forensics (IJCSDF)"},{"issue":"2","key":"13_CR5","first-page":"48","volume":"2","author":"FN Dezfoli","year":"2013","unstructured":"Dezfoli, F.N., Dehghantanha, A., Mahmoud, R., Sani, N.F.B.M., Daryabar, F.: Digital forensic trends and future. Int. J. Cyber-Secur. Digit. Forensics (IJCSDF) 2(2), 48\u201376 (2013)","journal-title":"Int. J. Cyber-Secur. Digit. Forensics (IJCSDF)"},{"key":"13_CR6","doi-asserted-by":"crossref","unstructured":"Damshenas, M., Dehghantanha, A., Mahmoud, R., bin Shamsuddin, S.: Forensics investigation challenges in cloud computing environments. In: 2012 International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec), pp. 190\u2013194. IEEE (2012)","DOI":"10.1109\/CyberSec.2012.6246092"},{"key":"13_CR7","doi-asserted-by":"crossref","unstructured":"Parvez, S., Dehghantanha, A., Broujerdi, H.G.: Framework of digital forensics for the samsung star series phone. In: 2011 3rd International Conference on Electronics Computer Technology (ICECT), vol. 2, pp. 264\u2013267. IEEE (2011)","DOI":"10.1109\/ICECTECH.2011.5941698"},{"key":"13_CR8","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1007\/978-3-642-32573-1_18","volume-title":"Signal Processing and Information Technology","author":"Y TzeTzuen","year":"2012","unstructured":"TzeTzuen, Y., Dehghantanha, A., Seddon, A., Mohtasebi, S.H.: Greening digital forensics: opportunities and challenges. In: Das, V.V., Ariwa, E., Rahayu, S.B. (eds.) SPIT 2011. LNICST, vol. 62, pp. 114\u2013119. Springer, Heidelberg (2012)"},{"issue":"3","key":"13_CR9","first-page":"645","volume":"1","author":"F Daryabar","year":"2011","unstructured":"Daryabar, F., Dehghantanha, A., Broujerdi, H.G.: Investigation of malware defence and detection techniques. Int. J. Digit. Inf. Wireless Commun. (IJDIWC) 1(3), 645\u2013650 (2011)","journal-title":"Int. J. Digit. Inf. Wireless Commun. (IJDIWC)"},{"issue":"3","key":"13_CR10","first-page":"651","volume":"1","author":"SH Mohtasebi","year":"2011","unstructured":"Mohtasebi, S.H., Dehghantanha, A., Broujerdi, H.G.: Smartphone forensics: a case study with Nokia E5-00 mobile phone. Int. J. Digit. Inf. Wireless Commun. (IJDIWC) 1(3), 651\u2013655 (2011)","journal-title":"Int. J. Digit. Inf. Wireless Commun. (IJDIWC)"},{"issue":"2","key":"13_CR11","doi-asserted-by":"publisher","first-page":"351","DOI":"10.7763\/IJCTE.2013.V5.708","volume":"5","author":"SH Mohtasebi","year":"2013","unstructured":"Mohtasebi, S.H., Dehghantanha, A.: Towards a unified forensic investigation framework of smartphones. Int. J. Comput. Theory Eng. 5(2), 351\u2013355 (2013)","journal-title":"Int. J. Comput. Theory Eng."},{"issue":"7","key":"13_CR12","doi-asserted-by":"publisher","first-page":"671","DOI":"10.1016\/j.knosys.2007.05.002","volume":"20","author":"M Saleh","year":"2007","unstructured":"Saleh, M., Arasteh, A.R., Sakha, A., Debbabi, M.: Forensic analysis of logs: modeling and verification. Knowl.-Based Syst. 20(7), 671\u2013682 (2007)","journal-title":"Knowl.-Based Syst."},{"key":"13_CR13","first-page":"15","volume":"50","author":"N Borhan","year":"2012","unstructured":"Borhan, N., Mahmod, R., Dehghantanha, A.: A framework of TPM, SVM and boot control for securing forensic logs. Int. J. Comput. Appl. 50, 15\u201319 (2012)","journal-title":"Int. J. Comput. Appl."},{"key":"13_CR14","series-title":"b","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1007\/978-3-642-33448-1_34","volume-title":"Global Security, Safety and Sustainability & e-Democracy","author":"NM Ibrahim","year":"2012","unstructured":"Ibrahim, N.M., Al-Nemrat, A., Jahankhani, H., Bashroush, H.: Sufficiency of windows event log as evidence in digital forensics. In: Georgiadis, C.K., Jahankhani, H., Pimenidis, E., Bashroush, R., Al-Nemrat, A. (eds.) ICGS3\/e-Democracy 2011. LNICST, vol. 99, pp. 253\u2013262. Springer, Heidelberg (2012)"},{"key":"13_CR15","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1016\/j.diin.2007.06.015","volume":"4","author":"A Schuster","year":"2007","unstructured":"Schuster, A.: Introducing the Microsoft Vista event log file format. Digit. Invest. 4, 65\u201372 (2007)","journal-title":"Digit. Invest."},{"key":"13_CR16","unstructured":"Guy Thomas.: Microsoft Windows 8 Event Viewer. Computer Performance LTD. http:\/\/www.computerperformance.co.uk\/win8\/windows8-event-viewer.htm"},{"key":"13_CR17","unstructured":"Microsoft Corporation, Redmond.: Event Logging. http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa363632(v=vs.85).aspx"},{"key":"13_CR18","unstructured":"Microsoft Corporation, Redmond.: Event Types. http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa363632(v=vs.85).aspx"},{"key":"13_CR19","unstructured":"Fleisher, E.: Windows 8 Forensics: Reset and Refresh Artifacts., cyber arms \u2013 computer security. http:\/\/www.computerperformance.co.uk\/win8\/windows8-event-viewer.htm"},{"key":"13_CR20","unstructured":"Brengle, M.: Working with the Event Viewer in Windows., 7 tutorials-Help & Howto for windows. http:\/\/www.7tutorials.com\/basics-about-working-event-viewer-windows"},{"key":"13_CR21","unstructured":"InsungPark, Buch, R.: Improve Debugging And Performance Tuning With ETW., MSDN Magazine. http:\/\/msdn.microsoft.com\/en-us\/magazine\/cc163437.aspx"},{"key":"13_CR22","unstructured":"Microsoft Corporation, Redmond.: What information appears in event logs. http:\/\/windows.microsoft.com\/en-us\/windows\/what-information-event-logs-event-viewer#1TC=windows-7"},{"key":"13_CR23","unstructured":"TZWorks Limited Liability Company.: Windows Event Log Viewer. TZWorksLLC. https:\/\/www.tzworks.net\/index.html"},{"key":"13_CR24","unstructured":"Microsoft Corporation, Redmond.: Event Logging. http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa363652(v=vs.85).aspx"},{"key":"13_CR25","unstructured":"Microsoft Corporation, Redmond.: Event Log File Format. http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/bb309026(v=vs.85).aspx"},{"key":"13_CR26","unstructured":"Von Schuster, A.: Evtx Data Types., Computer-Forensik. http:\/\/computer.forensikblog.de\/en\/2007\/08\/evtx-data-types.html"},{"key":"13_CR27","unstructured":"Verma, P.: Basics of Forensics Log Analysis., Information Security Intelligence. http:\/\/palizine.plynt.com\/issues\/2009Oct\/forensic-log-analysis\/"}],"container-title":["Lecture Notes in Computer Science","Computational Forensics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-20125-2_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,17]],"date-time":"2023-02-17T12:45:52Z","timestamp":1676637952000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-20125-2_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319201245","9783319201252"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-20125-2_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"27 June 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}