Collecting Network Evidence
The traditional focus of digital forensics has been on locating evidence on the suspect host's hard drive. Law enforcement officers interested in criminal activity such as fraud or child exploitation can find the evidence required for prosecution on a single hard drive. In the realm of incident response, though, it is critical that the focus goes far beyond a suspected compromised system. For example, there is a wealth of information that can be obtained within the hardware and software along with the flow of traffic from a compromised host to an external Command and Control (C2) server.
This chapter focuses on the preparation, identification, and collection of evidence that is commonly found among network devices ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access