Skip to Content
Digital Forensics and Incident Response - Third Edition
book

Digital Forensics and Incident Response - Third Edition

by Gerard Johansen
December 2022
Intermediate to advanced
532 pages
13h 54m
English
Packt Publishing
Content preview from Digital Forensics and Incident Response - Third Edition

9

Analyzing Network Evidence

Chapter 5 explored how incident responders and security analysts can acquire network-based evidence for later evaluation. That chapter focused on two primary sources of that evidence: network log files and network packet captures. This chapter will show you which tools and techniques are available to examine the evidence acquired. Incorporating these techniques into an incident response investigation can provide incident response analysts with insight into the network activity of possible threats.

In this chapter, the following main topics will be addressed:

  • Network evidence overview
  • Analyzing firewall and proxy logs
  • Analyzing NetFlow
  • Analyzing packet captures

Network evidence overview

Adversaries are bound to ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Digital Forensics and Incident Response - Fourth Edition

Digital Forensics and Incident Response - Fourth Edition

Gerard Johansen

Publisher Resources

ISBN: 9781803238678