Chapter 13

Reporting

Abstract

Using open source tools to collect memory and analyze it as part of a forensic investigation.

Keywords

operating systems
forensics
operating environments

INFORMATION INCLUDED IN THIS CHAPTER:

Writing Style
Artifacts
Reporting Considerations
Reporting Requirements
Report Samples
Testifying

Introduction

Once you have completed your investigation, no matter what type of investigation it is, you will probably have to generate a report. In other words, you want to convey your findings in a way that can be easily understood. You will probably have acquired a fair amount of data and you will not want to simply hand it all over. One of your tasks as a forensic investigator or incident responder is performing some ...

Get Operating System Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.