December 2013
Intermediate to advanced
616 pages
14h 38m
English
• Correlate the information gathered through the interception of system calls with artifacts discovered in file system activity.
• Correlate file system activity with process activity and digital trace evidence such as dropped executables, libraries, hidden files, and anomalous text or binary files.
Monitor common locations where malware manifests to blend into the system, such as /tmp, as it may reveal anomalous items.
In addition to such traditional malware file artifacts, consider functional context, including processes running from suspicious ...
Read now
Unlock full access