Summary
Throughout this chapter, we've covered a good number of useful tools that can assist the investigator or administrator in collecting information from systems. This information can be used for troubleshooting purposes, as well as for incident response and recovery activities. By now, it should be clear that there is a vast amount of information available on a system that can provide clues as to its state, such as whether it has been compromised or not. Now that we know what tools can be used to collect this information, Chapter 6 will present methodologies for collecting and analyzing the data that is collected.
Table 5-1 lists tools used to retrieve volatile information from a system. The tools listed in italics are native to the Windows ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access