Executing Windows Command Line Investigations: While Ensuring Evidentiary Integrity
暫譯: 執行 Windows 命令列調查:確保證據完整性
Chet Hosmer, Joshua Bartolomie, Rosanne Pelli
- 出版商: Syngress Media
- 出版日期: 2016-06-14
- 售價: $2,710
- 貴賓價: 9.5 折 $2,575
- 語言: 英文
- 頁數: 228
- 裝訂: Paperback
- ISBN: 0128092688
- ISBN-13: 9780128092682
-
相關分類:
Command Line
海外代購書籍(需單獨結帳)
商品描述
The book Executing Windows Command Line Investigations targets the needs of cyber security practitioners who focus on digital forensics and incident response. These are the individuals who are ultimately responsible for executing critical tasks such as incident response; forensic analysis and triage; damage assessments; espionage or other criminal investigations; malware analysis; and responding to human resource violations.
The authors lead readers through the importance of Windows CLI, as well as optimal configuration and usage. Readers will then learn the importance of maintaining evidentiary integrity, evidence volatility, and gain appropriate insight into methodologies that limit the potential of inadvertently destroying or otherwise altering evidence. Next, readers will be given an overview on how to use the proprietary software that accompanies the book as a download from the companion website. This software, called Proactive Incident Response Command Shell (PIRCS), developed by Harris Corporation provides an interface similar to that of a Windows CLI that automates evidentiary chain of custody and reduces human error and documentation gaps during incident response.
- Includes a free download of the Proactive Incident Response Command Shell (PIRCS) software
- Learn about the technical details of Windows CLI so you can directly manage every aspect of incident response evidence acquisition and triage, while maintaining evidentiary integrity
商品描述(中文翻譯)
本書《執行 Windows 命令列調查》針對專注於數位取證和事件回應的網路安全從業人員的需求。這些人員最終負責執行關鍵任務,例如事件回應、取證分析和分類、損害評估、間諜活動或其他刑事調查、惡意程式分析,以及應對人力資源違規行為。
作者引導讀者了解 Windows CLI 的重要性,以及最佳的配置和使用方式。讀者將學習維護證據完整性、證據易變性的重要性,並獲得適當的見解,了解限制意外破壞或改變證據潛在風險的方法論。接下來,讀者將獲得如何使用隨書附贈的專有軟體的概述,該軟體可從伴隨網站下載。這款名為 Proactive Incident Response Command Shell (PIRCS) 的軟體,由 Harris Corporation 開發,提供類似 Windows CLI 的介面,自動化證據鏈的保管,並減少事件回應過程中的人為錯誤和文檔缺口。
- 包含 Proactive Incident Response Command Shell (PIRCS) 軟體的免費下載
- 了解 Windows CLI 的技術細節,以便直接管理事件回應證據的獲取和分類,同時維護證據的完整性