Skip to Content
97 Things Every Information Security Professional Should Know
book

97 Things Every Information Security Professional Should Know

by Christina Morillo
September 2021
Beginner
264 pages
7h 48m
English
O'Reilly Media, Inc.
Content preview from 97 Things Every Information Security Professional Should Know

Chapter 48. If It’s Remembered for You, Forensics Can Uncover It

Lodrina Cherne

Our phones and computers aim to be more user friendly with every app and operating system upgrade, remembering the person you email the most, the file you recently opened, or the website you always visit. Because this tracking data makes devices more user friendly, it also means that forensic examiners have an increasing amount of data to draw from when investigating digital crime scenes.

If your device recommends doing something you’ve done before, these remembered actions are something that can be uncovered by a digital forensics examiner. By identifying what your devices remember, you’ll be better prepared to work with a forensic professional. Digital forensics and incident response (DFIR) is a field that involves figuring out what happened on a system or network after it happens. Here’s just a few examples of what our computers and mobile devices remember for us that forensics can recover:

  • Ever open your word processing app and see it recommend the last 10 files you worked on as things you might want to open again? Forensics can tell you when you opened those files.

  • Scroll through your open apps on a mobile device and see previews of those applications as you were last using them? The screenshots are recoverable by forensic analysis.

  • Do you like viewing your Downloads folder as a list of files ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Foundations of Information Security

Foundations of Information Security

Jason Andress

Publisher Resources

ISBN: 9781098101381Errata Page