商品描述
This practical and accessible textbook/reference describes the theory and methodology of digital forensic examinations, presenting examples developed in collaboration with police authorities to ensure relevance to real-world practice. The coverage includes discussions on forensic artifacts and constraints, as well as forensic tools used for law enforcement and in the corporate sector. Emphasis is placed on reinforcing sound forensic thinking, and gaining experience in common tasks through hands-on exercises.
This enhanced second edition has been expanded with new material on incident response tasks and computer memory analysis.
Topics and features:
- Outlines what computer forensics is, and what it can do, as well as what its limitations are
- Discusses both the theoretical foundations and the fundamentals of forensic methodology
- Reviews broad principles that are applicable worldwide
- Explains how to find and interpret several important artifacts
- Describes free and open source software tools, along with the AccessData Forensic Toolkit
- Features exercises and review questions throughout, with solutions provided in the appendices
- Includes numerous practical examples, and provides supporting video lectures online
This easy-to-follow primer is an essential resource for students of computer forensics, and will also serve as a valuable reference for practitioners seeking instruction on performing forensic examinations.
Joakim K vrestad is a lecturer and researcher at the University of Sk vde, Sweden, and an AccessData Certified Examiner. He also serves as a forensic consultant, with several years of experience as a forensic expert with the Swedish police.
商品描述(中文翻譯)
這本實用且易於理解的教科書/參考書描述了數位鑑識檢查的理論和方法論,並提供了與警方當局合作開發的範例,以確保與實務的相關性。內容涵蓋了對鑑識文物和限制的討論,以及在執法和企業部門中使用的鑑識工具。重點在於加強健全的鑑識思維,並通過實作練習獲得常見任務的經驗。
這個增強版的第二版擴充了有關事件響應任務和計算機記憶體分析的新材料。
主題和特點:
- 概述了計算機鑑識的定義、功能及其限制
- 討論了鑑識方法論的理論基礎和基本原則
- 回顧了適用於全球的廣泛原則
- 解釋如何找到和解釋幾個重要的文物
- 描述了免費和開源軟體工具,以及 AccessData Forensic Toolkit
- 在全書中提供練習和回顧問題,並在附錄中提供解答
- 包含大量實用範例,並提供線上支援的視頻講座
這本易於跟隨的入門書是計算機鑑識學生的重要資源,對於尋求進行鑑識檢查指導的從業者來說,也將是一本有價值的參考書。
Joakim K vrestad 是瑞典斯科夫德大學的講師和研究員,也是 AccessData 認證檢查員。他還擔任鑑識顧問,擁有多年作為瑞典警方鑑識專家的經驗。
作者簡介
Joakim Kävrestad is a lecturer and researcher at the University of Skövde, Sweden, and an AccessData Certified Examiner. He also serves as a forensic consultant, with several years of experience as a forensic expert with the Swedish police.
作者簡介(中文翻譯)
Joakim Kävrestad 是瑞典斯科夫德大學的講師和研究員,也是 AccessData 認證考官。他同時擔任法醫顧問,擁有多年擔任瑞典警方法醫專家的經驗。