Incident Response & Computer Forensics, 2nd Ed.
Chris Prosise, Kevin Mandia, Matt Pepe · McGraw-Hill, Inc. eBooks · 2003
Written by FBI insiders, this updated best-seller offers a look at the legal, procedural, and technical steps of incident response and computer forensics. Including new chapters on forensic analysis and remediation, and real-world case studies, this revealing book shows how to counteract and conquer today’s hack attacks. Table of contents Part I: Introduction 1: Real-World Incidents 2: Introduction to the Incident Response Process 3: Preparing for Incident Response 4: After Detection of an Incident Part II: Data Collection 5: Live Data Collection from Windows Systems 6: Live Data Collection from Unix Systems 7: Forensic Duplication 8: Collecting Network-based Evidence 9: Evidence Handling Part III: Data Analysis 10: Computer System Storage Fundamentals 11: Data Analysis Techniques 12: Investigating Windows Systems 13: Investigating Unix Systems 14: Analyzing Network Traffic 15: Investigating Hacker Tools 16: Investigating Routers 17: Writing Computer Forensic Reports Part IV: Appendixes A: Answers to Questions B: Incident Response Forms