Skip to Content
Digital Forensics Cookbook
book

Digital Forensics Cookbook

by Cody Bounds
March 2026
Intermediate
592 pages
14h 6m
English
Packt Publishing

Overview

Learn the workflows professionals use to triage systems, uncover hidden activity, recover deleted evidence, crack encrypted containers, analyze Windows memory, and detect tampering using realistic hands-on forensic datasets.

Key Features

  • Master field-tested workflows for triage, acquisition, and cross-platform analysis
  • Uncover hidden activity, recover evidence, defeat encryption, and detect tampering
  • Build hands-on investigation skills using realistic datasets across major platforms
  • Purchase of the print or Kindle book includes a free PDF ebook

Book Description

Modern investigations and incident response efforts live and die by digital evidence. Digital Forensics Cookbook uses realistic datasets and practical workflows drawn from real investigations to uncover the truth hidden inside computers, mobile devices, and online accounts.

Rather than focusing on theory alone, this book moves you through the investigative process from triage and acquisition to artifact analysis, memory forensics, encryption challenges, malware triage, and detecting anti-forensic behavior. Along the way, you’ll perform remote artifact collection, analyze evidence across Windows, macOS, Linux, iOS, and Android systems, investigate cloud-synced accounts, recover deleted data, manually carve evidence when tools fail, and identify attempts to hide or manipulate data.

As you progress through the book, you’ll learn how to write and apply regular expressions and SQLite queries, build system timelines, baseline systems, automate analysis, verify findings across independent sources, generate custom password dictionaries to crack encrypted containers, detect metadata tampering designed to mislead investigators, and analyze Windows memory. By the end, you won’t just know how to run forensic tools; you’ll understand how investigators think, enabling you to turn scattered digital traces into clear, defensible conclusions.

What you will learn

  • Perform triage and acquire evidence during live investigations
  • Collect artifacts remotely using incident response workflows
  • Analyze evidence across Windows, macOS, Linux, iOS, and Android
  • Recover deleted data and manually carve evidence when tools fail
  • Crack encrypted containers using custom password dictionaries
  • Use regex and SQLite queries to uncover hidden investigative clues
  • Detect anti-forensic techniques and metadata tampering
  • Analyze Windows memory using Volatility to uncover live artifacts

Who this book is for

This book is for digital forensic investigators, incident responders, and security professionals who want to build practical investigation skills using real-world workflows and realistic datasets. It’s also ideal for students and analysts entering the field who want hands-on experience recovering evidence, analyzing artifacts, and thinking like an investigator.

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Digital Forensics, Investigation, and Response 5E, 5th Edition

Digital Forensics, Investigation, and Response 5E, 5th Edition

Chuck Easttom
Learn Mobile Forensics

Learn Mobile Forensics

William Oettinger

Publisher Resources

ISBN: 9781805127550