October 2019
Intermediate to advanced
374 pages
13h 10m
English
The second type of tool helps CSIRT members collect technical information to support incident investigation and resolution. These tools enable forensic investigators to collect evidence of incident activity to discover what happened, why it happened, how to stop it from happening again, and whether any legal action can be taken against the incident source. These toolsets often provide the ability to discover traces of past activity in memory, stored on disks, or in log files. CSIRT members who are trained to use investigation software can be very valuable resources for your team. In many cases, the difference between a successful incident resolution and an unknown loss is the quality ...
Read now
Unlock full access