A. Boileau, Hit by a bus: Physical access attacks with FireWire (www.storm.net.nz/static/files/ab firewire rux2k6-final, 2006.

S. Brenner, B. Carrier, and J. Henninger, The Trojan Horse Defense in Cybercrime Cases, 2005.

B. Carrier, File System Forensic Analysis, Pearson, Upper Saddle River, 2005.

B. Carrier and J. Grand, A hardware-based memory acquisition procedure for digital investigations, Digital Investigation, pp.50-60, 2004.
DOI : 10.1016/j.diin.2003.12.001

H. Carvey, Windows Forensic Analysis, 2007.

B. Dolan-gavitt, Finding kernel global variables in Windows (mo yix.blogspot.com, 2008.

B. Dolan-gavitt, Forensic analysis of the Windows registry in memory, Digital Investigation, pp.26-32, 2008.
DOI : 10.1016/j.diin.2008.05.003

B. Dolan-gavitt, Linking processes to users (moyix.blogspot.comlinking-processes-to-users.html), 2008.

E. Libster and J. Kornblum, A proposal for an integrated memory acquisition mechanism, ACM SIGOPS Operating Systems Review, vol.42, issue.3, pp.14-20, 2008.
DOI : 10.1145/1368506.1368510

N. Institite and . Justice, Electronic Crime Scene Investigation: An On-the-Scene Reference for First Responders, 2009.

M. Russinovich, Sysinternals Suite, Microsoft Corporation

J. Rutkowska, Beyond the CPU: Defeating hardware-based RAM acquisition (Part I: AMD case), presented at the Black Hat DC 2007 Conference (www.first.org/conference, 2007.

A. Schuster, PTfinder (version 0.2.00), 2006.

A. Schuster, Searching for processes and threads in Microsoft Windows memory dumps, Digital Investigation, pp.10-16, 2006.
DOI : 10.1016/j.diin.2006.06.010

. Sourceforge, net, Memparser (sourceforge, 2006.

M. Suiche, Sandman Project (sandman.msuiche.net/docs/Sand Man Project, 2008.

I. Sutherland, J. Evans, T. Tryfonas, and A. Blyth, Acquiring volatile operating system data tools and techniques, ACM SIGOPS Operating Systems Review, vol.42, issue.3, pp.65-73, 2008.
DOI : 10.1145/1368506.1368516

A. Walters and N. Petroni, Volatools: Integrating volatile memory forensics into the digital investigation process, presented at Blackhat Hat DC 2007 Conference (www.blackhat.com/presentations/bh-dc- 07, 2007.