F-Response

Another option that is available to incident response analyst is the use of the tool F-Response. F-Response is a software platform that allows incident response analysts to perform remote acquisition of evidence over a network. One advantage to utilizing F-Response is that it does not require direct access via SSH or RDS to the remote system. Another key feature of F-Response is that the tool is designed to establish the connection while allowing the incident response analyst to utilize their preferred tools to perform the acquisition.

In the following example, F-Response is utilized to connect to a suspected compromised system over a network whereby the incident response analyst can utilize FTK Imager to acquire the memory of ...

Get Digital Forensics and Incident Response now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.