Another option that is available to incident response analyst is the use of the tool F-Response. F-Response is a software platform that allows incident response analysts to perform remote acquisition of evidence over a network. One advantage to utilizing F-Response is that it does not require direct access via SSH or RDS to the remote system. Another key feature of F-Response is that the tool is designed to establish the connection while allowing the incident response analyst to utilize their preferred tools to perform the acquisition.

In the following example, F-Response is utilized to connect to a suspected compromised system over a network whereby the incident response analyst can utilize FTK Imager to acquire the memory of ...

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.