Incident Response & Computer Forensics, Third Edition Logo

Incident Response & Computer Forensics, Third Edition

0
Free
Visit Website

This book provides a comprehensive guide to incident response and computer forensics, covering the entire lifecycle of incident response, including preparation, data collection, data analysis, and remediation. It includes real-world case studies and practical techniques for investigating and remediating data breaches. The book covers topics such as architecting an infrastructure for methodical investigation and remediation, developing leads and identifying indicators of compromise, collecting and preserving live data, performing forensic duplication, analyzing data from networks and applications, investigating Windows and Mac OS X systems, performing malware triage, writing detailed incident response reports, and creating comprehensive remediation plans.

FEATURES

ALTERNATIVES

Python forensic tool for extracting and analyzing information from Firefox, Iceweasel, and Seamonkey browsers.

A tool that uses Plaso to parse forensic artifacts and disk images, creating custom reports for easier analysis.

Easy-to-use live forensics toolbox for Linux endpoints with various capabilities such as process inspection, memory analysis, and YARA scanning.

A comprehensive incident response tool for Windows computers, providing advanced memory forensics and access to locked systems.

Create checkpoint snapshots of the state of running pods for later off-line analysis.

A digital forensic tool for creating forensic images of computer hard drives and analyzing digital evidence.

A simple Golang application for storing NIST National Software Reference Library Reference Data Set (NSRL RDS) with md5 and sha1 hash lookup searches.

DFIR ORC Documentation provides detailed instructions for setting up the build environment and deploying the tool.