Chapter 4. Incident Preparation

As with death and taxes, incidents are inevitable. It's a simple fact that incidents are going to happen. Systems or organizations connected to the public Internet will be scanned and probed for vulnerabilities, and if any are found, someone will try to exploit them. This pertains equally to corporate and university systems, as well as home user systems. New vulnerabilities are being discovered every day that affect both the operating systems and applications that are so prolific throughout the computing infrastructure. Once a new vulnerability has been discovered and the vendor (in this case, Microsoft) has been informed, a patch will be released, many times in short order. At that point, it is incumbent upon ...

Get Windows Forensics and Incident Recovery now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.