Skip to Content
Practical Linux Forensics
book

Practical Linux Forensics

by Bruce Nikkel
October 2021
Beginner to intermediate
400 pages
11h 15m
English
No Starch Press
Content preview from Practical Linux Forensics

3EVIDENCE FROM STORAGE DEVICES AND FILESYSTEMS

Image

This chapter focuses on the forensic analysis of Linux storage, including partition tables, volume management and RAID, filesystems, swap partitions and hibernation, and drive encryption. Each of these areas have Linux-specific artifacts that we can analyze. You may be able to use commercial forensic tools to perform most of the activities shown here, but for illustrative purposes, the examples in this chapter use Linux tools.

When performing a forensic analysis of a computer system’s storage, the first step is to identify precisely what is on the drive. We must understand the layout, formats, versions, ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Linux System Administration

Practical Linux System Administration

Kenneth Hess
Practical Windows Forensics

Practical Windows Forensics

Ayman Shaaban, Konstantin Sapronov
Malware Forensics Field Guide for Linux Systems

Malware Forensics Field Guide for Linux Systems

Eoghan Casey, Cameron H. Malin, James M. Aquilina

Publisher Resources

ISBN: 9781098129781