Digital Forensics and Incident Response
暫譯: 數位鑑識與事件回應
Gerard Johansen
- 出版商: Packt Publishing
- 出版日期: 2017-07-24
- 售價: $2,010
- 貴賓價: 9.5 折 $1,910
- 語言: 英文
- 頁數: 324
- 裝訂: Paperback
- ISBN: 1787288684
- ISBN-13: 9781787288683
-
其他版本:
Digital Forensics and Incident Response - Second Edition
買這商品的人也買了...
-
$1,190$1,131 -
$560$437 -
$450$356 -
$480$379
商品描述
Key Features
- Learn incident response fundamentals and create an effective incident response framework
- Master forensics investigation utilizing digital investigative techniques
- Contains real-life scenarios that effectively use threat intelligence and modeling techniques
Book Description
Digital Forensics and Incident Response will guide you through the entire spectrum of tasks associated with incident response, starting with preparatory activities associated with creating an incident response plan and creating a digital forensics capability within your own organization. You will then begin a detailed examination of digital forensic techniques including acquiring evidence, examining volatile memory, hard drive assessment, and network-based evidence. You will also explore the role that threat intelligence plays in the incident response process. Finally, a detailed section on preparing reports will help you prepare a written report for use either internally or in a courtroom.
By the end of the book, you will have mastered forensic techniques and incident response and you will have a solid foundation on which to increase your ability to investigate such incidents in your organization.
What you will learn
- Create and deploy an incident response capability within your organization
- Build a solid foundation in handling and acquiring suitable evidence for later analysis
- Analyze collected evidence and determine the root cause of a security incident
- Learn to integrate digital forensic techniques and procedures into the overall incident response process
- Integrate threat intelligence in digital evidence analysis
- Prepare written documentation for use internally or with external parties such as regulators or law enforcement agencies
商品描述(中文翻譯)
關鍵特點
- 學習事件回應的基本原則並建立有效的事件回應框架
- 精通利用數位調查技術進行取證調查
- 包含有效使用威脅情報和建模技術的實際案例
書籍描述
《數位取證與事件回應》將引導您了解與事件回應相關的所有任務,從創建事件回應計劃的準備活動開始,並在您自己的組織內建立數位取證能力。接著,您將詳細檢視數位取證技術,包括證據獲取、檢查易失性記憶體、硬碟評估和基於網路的證據。您還將探討威脅情報在事件回應過程中的角色。最後,關於準備報告的詳細部分將幫助您撰寫內部使用或在法庭上使用的書面報告。
在書籍結束時,您將掌握取證技術和事件回應,並擁有堅實的基礎,以提高您在組織中調查此類事件的能力。
您將學到的內容
- 在您的組織內創建和部署事件回應能力
- 建立處理和獲取適當證據以供後續分析的堅實基礎
- 分析收集的證據並確定安全事件的根本原因
- 學習將數位取證技術和程序整合到整體事件回應過程中
- 在數位證據分析中整合威脅情報
- 準備書面文件以供內部使用或與外部機構(如監管機構或執法機構)使用