Operating System Forensics (Paperback)
暫譯: 作業系統取證學 (平裝本)

Ric Messier

相關主題

商品描述

Operating System Forensics is the first book to cover all three critical operating systems for digital forensic investigations in one comprehensive reference. 

Users will learn how to conduct successful digital forensic examinations in Windows, Linux, and Mac OS, the methodologies used, key technical concepts, and the tools needed to perform examinations.

Mobile operating systems such as Android, iOS, Windows, and Blackberry are also covered, providing everything practitioners need to conduct a forensic investigation of the most commonly used operating systems, including technical details of how each operating system works and how to find artifacts.

This book walks you through the critical components of investigation and operating system functionality, including file systems, data recovery, memory forensics, system configuration, Internet access, cloud computing, tracking artifacts, executable layouts, malware, and log files. You'll find coverage of key technical topics like Windows Registry, /etc directory, Web browers caches, Mbox, PST files, GPS data, ELF, and more. Hands-on exercises in each chapter drive home the concepts covered in the book. You'll get everything you need for a successful forensics examination, including incident response tactics and legal requirements. Operating System Forensics is the only place you'll find all this covered in one book.

  • Covers digital forensic investigations of the three major operating systems, including Windows, Linux, and Mac OS
  • Presents the technical details of each operating system, allowing users to find artifacts that might be missed using automated tools
  • Hands-on exercises drive home key concepts covered in the book.
  • Includes discussions of cloud, Internet, and major mobile operating systems such as Android and iOS

商品描述(中文翻譯)

《操作系統取證》是第一本涵蓋數位取證調查中三個關鍵操作系統的綜合參考書籍。

使用者將學習如何在 Windows、Linux 和 Mac OS 中進行成功的數位取證檢查,包括所使用的方法論、關鍵技術概念以及執行檢查所需的工具。

本書還涵蓋了 Android、iOS、Windows 和 Blackberry 等行動操作系統,提供從業者進行最常用操作系統取證調查所需的一切,包括每個操作系統的技術細節以及如何尋找數位痕跡。

本書將引導您了解調查和操作系統功能的關鍵組成部分,包括檔案系統、數據恢復、記憶體取證、系統配置、網際網路存取、雲端運算、追蹤數位痕跡、可執行檔佈局、惡意軟體和日誌檔案。您將找到關鍵技術主題的涵蓋,如 Windows 註冊表、/etc 目錄、網頁瀏覽器快取、Mbox、PST 檔案、GPS 數據、ELF 等等。每章的實作練習強化了書中所涵蓋的概念。您將獲得成功進行取證檢查所需的一切,包括事件響應策略和法律要求。《操作系統取證》是您唯一能在一本書中找到所有這些內容的地方。

- 涵蓋三大主要操作系統的數位取證調查,包括 Windows、Linux 和 Mac OS
- 提供每個操作系統的技術細節,使用者可以找到自動化工具可能遺漏的數位痕跡
- 實作練習強化書中涵蓋的關鍵概念
- 包括雲端、網際網路及主要行動操作系統(如 Android 和 iOS)的討論