January 2020
Intermediate to advanced
448 pages
11h 42m
English
A great deal of Chapter 4, Collecting Network Evidence, covered the various methods to obtain packet captures from a range of sources and from a variety of locations. Packet captures contain a great deal of information that is potentially valuable to incident response analysts. Some of this information includes source and destination IP addresses, domains and ports, and the content of communications between hosts. In some instances, incident response analysts are able to reconstruct actual files, such as text documents and images, in these packet captures.
Read now
Unlock full access