Continuing the Post Mortem
Peter D. Stephenson · Computer Fraud & Security · 2003
Last column we got started on an actual incident post mortem by looking at the Identification Class of the DFRWS Framework. We characterized the identification of the attack using the Digital Investigation Process Language (DIPL) and then began to expand upon the investigation by mapping (in DIPL) the discovery of an attack packet by the victim’s UK office. This week we’ll move on to other classes in the Framework.