Skip to Content
Digital Forensics and Incident Response - Third Edition
book

Digital Forensics and Incident Response - Third Edition

by Gerard Johansen
December 2022
Intermediate to advanced
532 pages
13h 54m
English
Packt Publishing
Content preview from Digital Forensics and Incident Response - Third Edition

12

Analyzing Log Files

Chapter 3 contained a detailed discussion of Dr. Edmond Locard and his exchange principle. For review purposes, the central premise of Locard’s Exchange Principle is that when two objects come into contact with each other, they leave a trace. In the world of digital forensics, we have discussed the various locations and techniques that can be leveraged by responders in uncovering these traces from memory, hard drives, and network traffic. One location that provides a wealth of data that can be leveraged is that of log files. Actions are logged across a wide range of hardware and software. What is needed is for responders to understand how to acquire these logs, how to examine them, and what they detail. In doing so, they ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Digital Forensics and Incident Response - Fourth Edition

Digital Forensics and Incident Response - Fourth Edition

Gerard Johansen

Publisher Resources

ISBN: 9781803238678