Skip to Content
Practical Linux Forensics
book

Practical Linux Forensics

by Bruce Nikkel
October 2021
Beginner to intermediate
400 pages
11h 15m
English
No Starch Press
Content preview from Practical Linux Forensics

6RECONSTRUCTING SYSTEM BOOT AND INITIALIZATION

Image

This chapter covers the forensic analysis of the Linux system boot and initialization process. We’ll examine the early boot stages where the BIOS or UEFI firmware pass control to the bootloader, the loading and executing of the kernel, and systemd initialization of a running system. Also included here is analysis of power management activities like sleep and hibernation, and the final shutdown process of the system.

Analysis of Bootloaders

Traditional PCs used a BIOS (basic input/output system) chip to run code from the first sector of a disk to boot the computer. This first sector is called the ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Linux System Administration

Practical Linux System Administration

Kenneth Hess
Practical Windows Forensics

Practical Windows Forensics

Ayman Shaaban, Konstantin Sapronov
Malware Forensics Field Guide for Linux Systems

Malware Forensics Field Guide for Linux Systems

Eoghan Casey, Cameron H. Malin, James M. Aquilina

Publisher Resources

ISBN: 9781098129781