Practical Forensic Imaging : Securing Digital Evidence with Linux Tools 🔍
Bruce Nikkel No Starch Press, Incorporated, 1, 2016-09-01
英语 [en] · PDF · 11.4MB · 2016 · 📘 非小说类图书 · 🚀/lgli/lgrs/nexusstc/zlib · Save
描述
Storage media overview for postmortem acquisition -- Linux as a forensic acquisition platform -- Forensic image formats and acquisition tools -- Forensic imaging preparation and setup -- Attaching physical media to an acquisition host -- Forensic image acquisition -- Forensic image management -- Accessing logical, virtual, and operating system encrypted images -- Extracting subsets of forensic images
备用文件名
lgli/Bruce Nikkel;Practical Forensic Imaging Securing Digital Evidence with Linux Tools;;;No Starch Press;2016;;;English.pdf
备用文件名
lgrsnf/Bruce Nikkel;Practical Forensic Imaging Securing Digital Evidence with Linux Tools;;;No Starch Press;2016;;;English.pdf
备用文件名
zlib/Computers/Networking/Bruce Nikkel/Practical Forensic Imaging: Securing Digital Evidence with Linux Tools_2951646.pdf
备选作者
Nikkel, Bruce
备用版本
Penguin Random House LLC (Publisher Services), San Francisco, 2016
备用版本
United States, United States of America
备用版本
Sep 01, 2016
备用版本
1, PS, 2016
元数据中的注释
True PDF
元数据中的注释
0
元数据中的注释
lg1709206
元数据中的注释
{"edition":"1","isbns":["1593277938","1593278004","1593278012","9781593277932","9781593278007","9781593278014"],"last_page":320,"publisher":"No Starch Press"}
备用描述
Forensic image acquisition is an important part of postmortem incident response and evidence collection. Digital forensic investigators acquire, preserve, and manage digital evidence to support civil and criminal cases; examine organizational policy violations; resolve disputes; and analyze cyber attacks.
Practical Forensic Imaging takes a detailed look at how to secure and manage digital evidence using Linux-based command line tools. This essential guide walks you through the entire forensic acquisition process and covers a wide range of practical scenarios and situations related to the imaging of storage media.
You’ll learn how to:
• Perform forensic imaging of magnetic hard disks, SSDs and flash drives, optical discs, magnetic tapes, and legacy technologies
• Protect attached evidence media from accidental modification
• Manage large forensic image files, storage capacity, image format conversion, compression, splitting, duplication, secure transfer and storage, and secure disposal
• Preserve and verify evidence integrity with cryptographic and piecewise hashing, public key signatures, and RFC-3161 timestamping
• Work with newer drive and interface technologies like NVME, SATA Express, 4K-native sector drives, SSHDs, SAS, UASP/USB3x, and Thunderbolt
• Manage drive security such as ATA passwords; encrypted thumb drives; Opal self-encrypting drives; OS-encrypted drives using BitLocker, FileVault, and TrueCrypt; and others
• Acquire usable images from more complex or challenging situations such as RAID systems, virtual machine images, and damaged media
With its unique focus on digital forensic acquisition and evidence preservation, Practical Forensic Imaging is a valuable resource for experienced digital forensic investigators wanting to advance their Linux skills and experienced Linux administrators wanting to learn digital forensics. This is a must-have reference for every digital forensics lab.
开源日期
2017-07-11
更多信息……

🚀 快速下载

成为会员以支持书籍、论文等的长期保存。为了感谢您对我们的支持,您将获得高速下载权益。❤️
如果您在本月捐款,您将获得双倍的快速下载次数。

🐢 低速下载

由可信的合作方提供。 更多信息请参见常见问题解答。 (可能需要验证浏览器——无限次下载!)

所有选项下载的文件都相同,应该可以安全使用。即使这样,从互联网下载文件时始终要小心。例如,确保您的设备更新及时。
  • 对于大文件,我们建议使用下载管理器以防止中断。
    推荐的下载管理器:JDownloader
  • 您将需要一个电子书或 PDF 阅读器来打开文件,具体取决于文件格式。
    推荐的电子书阅读器:Anna的档案在线查看器ReadEraCalibre
  • 使用在线工具进行格式转换。
    推荐的转换工具:CloudConvertPrintFriendly
  • 您可以将 PDF 和 EPUB 文件发送到您的 Kindle 或 Kobo 电子阅读器。
    推荐的工具:亚马逊的“发送到 Kindle”djazz 的“发送到 Kobo/Kindle”
  • 支持作者和图书馆
    ✍️ 如果您喜欢这个并且能够负担得起,请考虑购买原版,或直接支持作者。
    📚 如果您当地的图书馆有这本书,请考虑在那里免费借阅。