Chapter 9

Introduction to Digital Forensics

This chapter covers the following topics:

Introduction to Digital Forensics

The Role of Attribution in a Cybersecurity Investigation

The Use of Digital Evidence

Evidentiary Chain of Custody

Reverse Engineering

Fundamentals of Microsoft Windows Forensics

Fundamentals of Linux Forensics

This chapter introduces digital forensics and defines the role of attribution in a cybersecurity investigation. You also learn the use of digital evidence as well as the fundamentals of Microsoft Windows and Linux forensics.

“Do I Know This Already?” Quiz

The “Do I Know This Already?” quiz allows you to assess whether you should read this entire chapter thoroughly or jump to the “Exam Preparation Tasks” section. If you ...

Get Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.