Chapter 5. Using Python for Virtualization Forensics
Currently, virtualization is one of the most trending concepts of modern IT. For forensic analysis, it introduces new challenges as well as new techniques.
In this chapter, we will show how virtualization introduces the following:
- New attack vectors
- New chances of gathering evidence
- New targets for forensic analysis such as the virtualization layer
- New sources for forensic data
Considering virtualization as a new attack surface
Before we start with a forensic analysis, it is important to understand what to look for. With virtualization, there are new attack vectors and scenarios that are introduced. In the following sections, we will describe some of the scenarios and how to look for the corresponding ...
Get Mastering Python Forensics now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.