Skip to Content
Digital Forensics and Incident Response - Third Edition
book

Digital Forensics and Incident Response - Third Edition

by Gerard Johansen
December 2022
Intermediate to advanced
532 pages
13h 54m
English
Packt Publishing
Content preview from Digital Forensics and Incident Response - Third Edition

6

Acquiring Host-Based Evidence

Host systems are the targets of malicious actions far too often. Host systems represent a possible initial target so that someone can gain a foothold in the network or a pivot point for additional attacks, or the end goal of threat actors. As a result, incident response analysts should be prepared to investigate these systems. Modern operating systems such as Microsoft Windows create a variety of evidentiary artifacts during the execution of an application, when changes to files are made, or when user accounts are added. All these changes leave traces of activity that can be evaluated by incident response analysts. The amount of data that’s available to incident response analysts is increasing as storage and memory ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Digital Forensics and Incident Response - Fourth Edition

Digital Forensics and Incident Response - Fourth Edition

Gerard Johansen

Publisher Resources

ISBN: 9781803238678