What you need for this book

Readers must be aware of the basics of operating systems such as Linux and Windows as well as networking concepts such as TCP/IP and routers.

The book uses the following software:

  • Tcpdump with the libpcap library
  • Wireshark
  • FTK Imager (AccessData)
  • NetworkMiner for passive network sniffing
  • SNORT for evidence acquisition in the NIDS/NIPS mode
  • Splunk to collect and analyze log files
  • Squid as an open-source proxy
  • YARA to help identify malware

Get Learning Network Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.