Digital Forensics and Incident Response - Third Edition: Incident response tools and techniques for effective cyber threat response
暫譯: 數位鑑識與事件回應(第三版):有效的網路威脅回應工具與技術

Johansen, Gerard

  • 出版商: Packt Publishing
  • 出版日期: 2022-12-16
  • 售價: $2,200
  • 貴賓價: 9.5$2,090
  • 語言: 英文
  • 頁數: 532
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1803238674
  • ISBN-13: 9781803238678
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

相關主題

商品描述

Build your organization's cyber defense system by effectively applying digital forensics, incident management, and investigation techniques to real-world cyber threats


Key Features:

  • Create a solid incident response framework and manage cyber incidents effectively
  • Learn to apply digital forensics tools and techniques to investigate cyber threats
  • Explore the real-world threat of ransomware and apply proper incident response techniques for investigation and recovery


Book Description:

An understanding of how digital forensics integrates with the overall response to cybersecurity incidents is key to securing your organization's infrastructure from attacks. This updated third edition will help you perform cutting-edge digital forensic activities and incident response with a new focus on responding to ransomware attacks.

After covering the fundamentals of incident response that are critical to any information security team, you'll explore incident response frameworks. From understanding their importance to creating a swift and effective response to security incidents, the book will guide you using examples. Later, you'll cover digital forensic techniques, from acquiring evidence and examining volatile memory through to hard drive examination and network-based evidence. You'll be able to apply these techniques to the current threat of ransomware. As you progress, you'll discover the role that threat intelligence plays in the incident response process. You'll also learn how to prepare an incident response report that documents the findings of your analysis. Finally, in addition to various incident response activities, the book will address malware analysis and demonstrate how you can proactively use your digital forensic skills in threat hunting.

By the end of this book, you'll be able to investigate and report unwanted security breaches and incidents in your organization.


What You Will Learn:

  • Create and deploy an incident response capability within your own organization
  • Perform proper evidence acquisition and handling
  • Analyze the evidence collected and determine the root cause of a security incident
  • Integrate digital forensic techniques and procedures into the overall incident response process
  • Understand different techniques for threat hunting
  • Write incident reports that document the key findings of your analysis
  • Apply incident response practices to ransomware attacks
  • Leverage cyber threat intelligence to augment digital forensics findings


Who this book is for:

This book is for cybersecurity and information security professionals who want to implement digital forensics and incident response in their organizations. You'll also find the book helpful if you're new to the concept of digital forensics and looking to get started with the fundamentals. A basic understanding of operating systems and some knowledge of networking fundamentals are required to get started with this book.

商品描述(中文翻譯)

透過有效應用數位鑑識、事件管理和調查技術,建立您組織的網路防禦系統,以應對現實世界的網路威脅

主要特點:


  • 建立穩固的事件回應框架,有效管理網路事件

  • 學習應用數位鑑識工具和技術來調查網路威脅

  • 探索勒索病毒的現實威脅,並應用適當的事件回應技術進行調查和恢復

書籍描述:
了解數位鑑識如何與整體的網路安全事件回應整合,是保護您組織基礎設施免受攻擊的關鍵。本書的第三版經過更新,將幫助您執行尖端的數位鑑識活動和事件回應,並著重於應對勒索病毒攻擊。

在介紹任何資訊安全團隊至關重要的事件回應基本原則後,您將探索事件回應框架。從理解其重要性到創建快速有效的安全事件回應,本書將通過範例指導您。接下來,您將學習數位鑑識技術,從證據獲取和檢查易失性記憶體,到硬碟檢查和基於網路的證據。您將能夠將這些技術應用於當前的勒索病毒威脅。隨著進展,您將發現威脅情報在事件回應過程中的角色。您還將學習如何準備事件回應報告,記錄分析結果。最後,除了各種事件回應活動外,本書還將討論惡意軟體分析,並展示如何主動利用您的數位鑑識技能進行威脅獵捕。

在本書結束時,您將能夠調查並報告您組織內的不當安全漏洞和事件。

您將學到的內容:


  • 在您自己的組織內創建和部署事件回應能力

  • 執行適當的證據獲取和處理

  • 分析收集的證據並確定安全事件的根本原因

  • 將數位鑑識技術和程序整合到整體事件回應過程中

  • 了解不同的威脅獵捕技術

  • 撰寫事件報告,記錄分析的關鍵發現

  • 將事件回應實踐應用於勒索病毒攻擊

  • 利用網路威脅情報增強數位鑑識的發現

本書適合誰:
本書適合希望在其組織中實施數位鑑識和事件回應的網路安全和資訊安全專業人士。如果您對數位鑑識的概念感到陌生並希望從基本知識開始,本書也將對您有所幫助。開始閱讀本書需要對作業系統有基本了解,以及對網路基本知識有一定認識。