Chapter 4. Intrusion Investigation
Eoghan Casey, Christopher Daywalt and Andy Johnston
Contents
Case Management and Reporting
157 Common Initial Observations
170 Analyzing Digital Evidence
179 Combination/Correlation
191 Feeding Analysis Back into the Detection Phase
202Introduction
Intrusion investigation is a specialized subset of digital forensic investigation that is focused on determining the nature and full extent of unauthorized access and usage of one or more computer systems. We treat this subject with its own chapter due to the specialized nature of investigating this type of activity, and because of the high prevalence of computer ...