Practical Linux Forensics: A Guide for Digital Investigators 303146

Код товару: 303146Паперова книга
  • ISBN
    978-1718501966
  • Бренд
  • Автор
  • Рік
    2021
  • Мова
    Англійська
  • Ілюстрації
    Чорно-білі
A resource to help forensic investigators locate, analyze, and understand digital evidence found on modern Linux systems after a crime, security incident or cyber attack.

Practical Linux Forensics dives into the technical details of analyzing postmortem forensic images of Linux systems which have been misused, abused, or the target of malicious attacks. It helps forensic investigators locate and analyze digital evidence found on Linux desktops, servers, and IoT devices. Throughout the book, you learn how to identify digital artifacts which may be of interest to an investigation, draw logical conclusions, and reconstruct past activity from incidents. You’ll learn how Linux works from a digital forensics and investigation perspective, and how to interpret evidence from Linux environments. The techniques shown are intended to be independent of the forensic analysis platforms and tools used.

Learn how to:
  • Extract evidence from storage devices and analyze partition tables, volume managers, popular Linux filesystems (Ext4, Btrfs, and Xfs), and encryption
  • Investigate evidence from Linux logs, including traditional syslog, the systemd journal, kernel and audit logs, and logs from daemons and applications
  • Reconstruct the Linux startup process, from boot loaders (UEFI and Grub) and kernel initialization, to systemd unit files and targets leading up to a graphical login
  • Perform analysis of power, temperature, and the physical environment of a Linux machine, and find evidence of sleep, hibernation, shutdowns, reboots, and crashes
  • Examine installed software, including distro installers, package formats, and package management systems from Debian, Fedora, SUSE, Arch, and other distros
  • Perform analysis of time and Locale settings, internationalization including language and keyboard settings, and geolocation on a Linux system
  • Reconstruct user login sessions (shell, X11 and Wayland), desktops (Gnome, KDE, and others) and analyze keyrings, wallets, trash cans, clipboards, thumbnails, recent files and other desktop artifacts
  • Analyze network configuration, including interfaces, addresses, network managers, DNS, wireless artifacts (Wi-Fi, Bluetooth, WWAN), VPNs (including WireGuard), firewalls, and proxy settings
  • Identify traces of attached peripheral devices (PCI, USB, Thunderbolt, Bluetooth) including external storage, cameras, and mobiles, and reconstruct printing and scanning activity

About the Author
Bruce Nikkel is a professor at the Bern University of Applied Sciences in Switzerland, specializing in digital forensics and cybercrime. He is co-head of the university’s research institute for cybersecurity and engineering, and director of the Masters program in Digital Forensics and Cyber Investigation. In addition to his academic work, he has worked in risk and security departments at a global financial institution since 1997. He headed the bank's Cybercrime Intelligence & Forensic Investigation team for more than 15 years and currently works as an advisor. Bruce holds a PhD in network forensics, is the author of Practical Forensic Imaging (No Starch Press, 2016), and is an editor with Forensic Science International’s Digital Investigation journal. He has been a Unix and Linux enthusiast since the 1990s.
750 ₴
Купити
Monobank
до 10 платежей
от 84 ₴ / міс.
  • Нова Пошта
    Безкоштовно від 3'000,00 ₴
  • Укрпошта
    Безкоштовно від 1'000,00 ₴
  • Meest Пошта
    Безкоштовно від 3'000,00 ₴
Practical Linux Forensics: A Guide for Digital Investigators - фото 1
Інші книги No Starch Press

Характеристики

  • Бренд
  • Автор
  • Категорія
    Програмування
  • Рік
    2021
  • Сторінок
    400
  • Формат
    165х235 мм
  • Обкладинка
    М'яка
  • Тип паперу
    Офсетний
  • Мова
    Англійська
  • Ілюстрації
    Чорно-білі

Від видавця

A resource to help forensic investigators locate, analyze, and understand digital evidence found on modern Linux systems after a crime, security incident or cyber attack.

Practical Linux Forensics dives into the technical details of analyzing postmortem forensic images of Linux systems which have been misused, abused, or the target of malicious attacks. It helps forensic investigators locate and analyze digital evidence found on Linux desktops, servers, and IoT devices. Throughout the book, you learn how to identify digital artifacts which may be of interest to an investigation, draw logical conclusions, and reconstruct past activity from incidents. You’ll learn how Linux works from a digital forensics and investigation perspective, and how to interpret evidence from Linux environments. The techniques shown are intended to be independent of the forensic analysis platforms and tools used.

Learn how to:
  • Extract evidence from storage devices and analyze partition tables, volume managers, popular Linux filesystems (Ext4, Btrfs, and Xfs), and encryption
  • Investigate evidence from Linux logs, including traditional syslog, the systemd journal, kernel and audit logs, and logs from daemons and applications
  • Reconstruct the Linux startup process, from boot loaders (UEFI and Grub) and kernel initialization, to systemd unit files and targets leading up to a graphical login
  • Perform analysis of power, temperature, and the physical environment of a Linux machine, and find evidence of sleep, hibernation, shutdowns, reboots, and crashes
  • Examine installed software, including distro installers, package formats, and package management systems from Debian, Fedora, SUSE, Arch, and other distros
  • Perform analysis of time and Locale settings, internationalization including language and keyboard settings, and geolocation on a Linux system
  • Reconstruct user login sessions (shell, X11 and Wayland), desktops (Gnome, KDE, and others) and analyze keyrings, wallets, trash cans, clipboards, thumbnails, recent files and other desktop artifacts
  • Analyze network configuration, including interfaces, addresses, network managers, DNS, wireless artifacts (Wi-Fi, Bluetooth, WWAN), VPNs (including WireGuard), firewalls, and proxy settings
  • Identify traces of attached peripheral devices (PCI, USB, Thunderbolt, Bluetooth) including external storage, cameras, and mobiles, and reconstruct printing and scanning activity

About the Author
Bruce Nikkel is a professor at the Bern University of Applied Sciences in Switzerland, specializing in digital forensics and cybercrime. He is co-head of the university’s research institute for cybersecurity and engineering, and director of the Masters program in Digital Forensics and Cyber Investigation. In addition to his academic work, he has worked in risk and security departments at a global financial institution since 1997. He headed the bank's Cybercrime Intelligence & Forensic Investigation team for more than 15 years and currently works as an advisor. Bruce holds a PhD in network forensics, is the author of Practical Forensic Imaging (No Starch Press, 2016), and is an editor with Forensic Science International’s Digital Investigation journal. He has been a Unix and Linux enthusiast since the 1990s.

Відгуки про Practical Linux Forensics: A Guide for Digital Investigators

Practical Linux Forensics: A Guide for Digital Investigators
Practical Linux Forensics: A Guide for Digital Investigators
750 ₴
Купити
Персонально для вас
Dive Into Systems: A Gentle Introduction to Computer Systems
303114
Suzanne J. MatthewsTia NewhallKevin C. Webb
950 ₴
Linux Basics for Hackers, 2nd Edition
303136
OccupyTheWeb
1'200 ₴
The Book of Batch Scripting: From Fundamentals to Advanced Automation
283838
Jack McLarney
1'700 ₴
Programming C# 10: Build Cloud, Web, and Desktop Applications 1st Edition
197697
Ian Griffiths
1'900 ₴
Extending Power BI with Python and R - Second Edition: Perform advanced analysis using the power of analytical languages 2nd ed. Edition
275538
Luca Zavarella
1'600 ₴
Game Programming Patterns
88098
Robert Nystrom
1'800 ₴
Mastering Blockchain. Unlocking the Power of Cryptocurrencies, Smart Contracts, and Decentralized Applications. 1st Ed.
244773
Lorne Lantz, Daniel Cawrey
2'600 ₴
Beginning C++ Compilers: An Introductory Guide to Microsoft C/C++ and MinGW Compilers 1st ed. Edition
269656
Berik I. TuleuovAdemi B. Ospanova
1'300 ₴
Mobile DevOps Playbook: A practical guide for delivering high-quality mobile applications like a pro
264544
Moataz Nabil
1'300 ₴
Beginning Azure Functions: Building Scalable and Serverless Apps 2nd ed. Edition
263214
Rahul SawhneyKalyan Chanumolu
1'700 ₴
Getting Started with FPGAs: Digital Circuit Design, Verilog, and VHDL for Beginners
303175
Russell Merrick
1'300 ₴
Mastering REST APIs: Boosting Your Web Development Journey with Advanced API Techniques First Edition
286399
Siva Selvaraj
2'000 ₴