Limited Offer
Digital Forensics with Open Source Tools
- 1st Edition - March 29, 2011
- Authors: Harlan Carvey, Cory Altheide
- Language: English
- Paperback ISBN:9 7 8 - 1 - 5 9 7 4 9 - 5 8 6 - 8
- eBook ISBN:9 7 8 - 1 - 5 9 7 4 9 - 5 8 7 - 5
Digital Forensics with Open Source Tools is the definitive book on investigating and analyzing computer systems and media using open source tools. The book is a technical procedura… Read more
Purchase options
Institutional subscription on ScienceDirect
Request a sales quoteDigital Forensics with Open Source Tools is the definitive book on investigating and analyzing computer systems and media using open source tools. The book is a technical procedural guide, and explains the use of open source tools on Mac, Linux and Windows systems as a platform for performing computer forensics. Both well-known and novel forensic methods are demonstrated using command-line and graphical open source computer forensic tools for examining a wide range of target systems and artifacts.
Written by world-renowned forensic practitioners, this book uses the most current examination and analysis techniques in the field. It consists of 9 chapters that cover a range of topics such as the open source examination platform; disk and file system analysis; Windows systems and artifacts; Linux systems and artifacts; Mac OS X systems and artifacts; Internet artifacts; and automating analysis and extending capabilities. The book lends itself to use by students and those entering the field who do not have means to purchase new tools for different investigations.
This book will appeal to forensic practitioners from areas including incident response teams and computer forensic investigators; forensic technicians from legal, audit, and consulting firms; and law enforcement agencies.
- Written by world-renowned forensic practitioners
- Details core concepts and techniques of forensic file system analysis
- Covers analysis of artifacts from the Windows, Mac, and Linux operating systems
Forensic Practitioners from areas including: Incident response teams and computer forensic investigators, forensic technicians from legal, audit, and consulting firms, and law enforcement agencies
About the Authors
Acknowledgments
Cory Altheide
Harlan Carvey
Introduction
Intended Audience
Layout of the Book
What is not Covered
Chapter 1. Digital Forensics with Open Source Tools
Welcome to “Digital Forensics with Open Source Tools”
What is “Digital Forensics?”
What is “Open Source?”
Benefits of Open Source Tools
Summary
References
Chapter 2. Open Source Examination Platform
Preparing the Examination System
Using Linux as the Host
Using Windows as the Host
Summary
References
Chapter 3. Disk and File System Analysis
Media Analysis Concepts
The Sleuth Kit
Partitioning and Disk Layouts
Special Containers
Hashing
Carving
Forensic Imaging
Summary
References
Chapter 4. Windows Systems and Artifacts
Introduction
Windows File Systems
Registry
Event Logs
Prefetch Files
Shortcut Files
Windows Executables
Summary
References
Chapter 5. Linux Systems and Artifacts
Introduction
Linux File Systems
Linux Boot Process and Services
Linux System Organization and Artifacts
User Accounts
Home Directories
Logs
Scheduling Tasks
Summary
References
Chapter 6. Mac OS X Systems and Artifacts
Introduction
OS X File System Artifacts
OS X System Artifacts
User Artifacts
Summary
References
Chapter 7. Internet Artifacts
Introduction
Browser Artifacts
Mail Artifacts
Summary
References
Chapter 8. File Analysis
File Analysis Concepts
Images
Audio
Video
Archives
Documents
Summary
References
Chapter 9. Automating Analysis and Extending Capabilities
Introduction
Graphical Investigation Environments
Automating Artifact Extraction
Timelines
Summary
References
Appendix A. Free, Non-open Tools of Note
Introduction
Chapter 3: Disk and File System Analysis
Chapter 4: Windows Systems and Artifacts
Chapter 7: Internet Artifacts
Chapter 8: File Analysis
Chapter 9: Automating Analysis and Extending Capabilities
Validation and Testing Resources
Index
- No. of pages: 288
- Language: English
- Edition: 1
- Published: March 29, 2011
- Imprint: Syngress
- Paperback ISBN: 9781597495868
- eBook ISBN: 9781597495875
HC
Harlan Carvey
CA