{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T21:11:07Z","timestamp":1725570667624},"publisher-location":"Berlin, Heidelberg","reference-count":9,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642155055"},{"type":"electronic","value":"9783642155062"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-15506-2_6","type":"book-chapter","created":{"date-parts":[[2010,11,26]],"date-time":"2010-11-26T12:20:33Z","timestamp":1290774033000},"page":"77-90","source":"Crossref","is-referenced-by-count":4,"title":["A Consistency Study of the Windows Registry"],"prefix":"10.1007","author":[{"given":"Yuandong","family":"Zhu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joshua","family":"James","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pavel","family":"Gladyshev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","volume-title":"Windows Forensic Analysis","author":"H. Carvey","year":"2007","unstructured":"H. Carvey, Windows Forensic Analysis, Syngress, Burlington, Massachusetts, 2007."},{"key":"6_CR2","unstructured":"M. Geiger and F. Cranor, Counter-Forensic Privacy Tools: A Forensic Evaluation, Technical Report CMU-ISRI-05-119, Institute for Software Research International, Carnegie-Mellon University, Pittsburgh, Pennsylvania (reports-archive.adm.cs.cmu.edu\/anon\/isri2005\/CMU-ISRI-05-119.pdf), 2005."},{"issue":"2","key":"6_CR3","first-page":"1","volume":"6","author":"P. Gladyshev","year":"2007","unstructured":"P. Gladyshev and A. Enbacka, Rigorous development of automated inconsistency checks for digital evidence using the B method, International Journal of Digital Evidence, vol. 6(2), pp. 1\u201321, 2007.","journal-title":"International Journal of Digital Evidence"},{"issue":"2","key":"6_CR4","first-page":"1","volume":"4","author":"P. Gladyshev","year":"2005","unstructured":"P. Gladyshev and A. Patel, Formalizing event time bounding in digital investigations, International Journal of Digital Evidence, vol. 4(2), pp. 1\u201314, 2005.","journal-title":"International Journal of Digital Evidence"},{"issue":"1","key":"6_CR5","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1016\/j.diin.2007.01.005","volume":"4","author":"S. Hilley","year":"2007","unstructured":"S. Hilley, Anti-forensics with a small army of exploits, Digital Investigation, vol. 4(1), pp. 13\u201315, 2007.","journal-title":"Digital Investigation"},{"key":"6_CR6","unstructured":"Microsoft Corporation, Windows registry information for advanced users, Redmond, Washington (support.microsoft.com\/kb\/256986), 2008."},{"key":"6_CR7","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/978-0-387-84927-0_7","volume-title":"Advances in Digital Forensics IV","author":"S. Willassen","year":"2008","unstructured":"S. Willassen, Hypothesis-based investigation of digital timestamps, in Advances in Digital Forensics IV, I. Ray and S. Shenoi (Eds.), Springer, Boston, Massachusetts, pp. 75\u201386, 2008."},{"issue":"S1","key":"6_CR8","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1016\/j.diin.2009.06.009","volume":"6","author":"Y. Zhu","year":"2009","unstructured":"Y. Zhu, P. Gladyshev and J. James, Using ShellBag information to reconstruct user activities, Digital Investigation, vol. 6(S1), pp. S69\u2013S77, 2009.","journal-title":"Digital Investigation"},{"issue":"1-2","key":"6_CR9","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1016\/j.diin.2009.02.004","volume":"6","author":"Y. Zhu","year":"2009","unstructured":"Y. Zhu, J. James and P. Gladyshev, A comparative methodology for the reconstruction of digital events using Windows restore points, Digital Investigation, vol. 6(1-2), pp. 8\u201315, 2009.","journal-title":"Digital Investigation"}],"container-title":["IFIP Advances in Information and Communication Technology","Advances in Digital Forensics VI"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-15506-2_6.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,30]],"date-time":"2021-04-30T12:55:59Z","timestamp":1619787359000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-15506-2_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642155055","9783642155062"],"references-count":9,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-15506-2_6","relation":{},"ISSN":["1868-4238","1861-2288"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1861-2288"}],"subject":[],"published":{"date-parts":[[2010]]}}}