Résumé
Linux Forensics is the most comprehensive and up-to-date resource for those wishing to quickly and efficiently perform forensics on Linux systems. It is also a great asset for anyone that would like to better understand Linux internals.Linux Forensics will guide you step by step through the process of investigating a computer running Linux. Everything you need to know from the moment you receive the call from someone who thinks they have been attacked until the final report is written is covered in this book. All of the tools discussed in this book are free and most are also open source.Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Linux systems. While readers will have a strong grasp of Python and shell scripting by the time they complete this book, no prior knowledge of either of these scripting languages is assumed. Linux Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images. Linux Forensics contains extensive coverage of Linux ext2, ext3, and ext4 filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussions of advanced attacks and malware analysis round out the book.Book Highlights 370 pages in large, easy-to-read 8.5 x 11 inch formatOver 9000 lines of Python scripts with explanationsOver 800 lines of shell scripts with explanationsA 102 page chapter containing up-to-date information on the ext4 filesystemTwo scenarios described in detail with images available from the book websiteAll scripts and other support files are available from the book websiteChapter Contents First StepsGeneral PrinciplesPhases of InvestigationHigh-level ProcessBuilding a ToolkitDetermining If There Was an IncidentOpening a CaseTalking to UsersDocumenationMounting Known-good BinariesMinimizing Disturbance to the SubjectAutomation With ScriptingLive AnalysisGetting MetadataUsing SpreadsheetsGetting Command HistoriesGetting LogsUsing HashesDumping RAMCreating ImagesShutting Down the SystemImage FormatsDDDCFLDDWrite BlockingImaging Virtual MachinesImaging Physical DrivesMounting ImagesMaster Boot Record Based PartionsGUID Partition TablesMounting Partitions In LinuxAutomating With PythonAnalyzing Mounted ImagesGetting TimestampsUsing LibreOfficeUsing MySQLCreating TimelinesExtended FilesystemsBasicsSuperblocksFeaturesUsing PythonFinding Things That Are Out Of PlaceInodesJournalingMemory AnalysisVolatilityCreating ProfilesLinux CommandsDealing With More Advanced AttackersMalwareIs It Malware?Malware Analysis ToolsStatic AnalysisDynamic AnalysisObfuscationThe Road AheadLearning MoreCommunitiesConferencesCertifications
À propos de l'auteur
Polstra, Dr. Philip
Dr. Philip Polstra (known to his friends as Dr. Phil) is an internationally recognized hardware hacker. His work has been presented at numerous conferences around the globe including repeat performances at DEFCON (six presentations in four years), BlackHat, 44CON, GrrCON, MakerFaire, ForenSecure, and other top conferences. Dr. Polstra is a well-known expert on USB forensics and has published several articles on this topic. He has developed a number of video courses including ones on Linux forensics, USB forensics, and reverse engineering. Dr. Polstra has developed degree programs in digital forensics and ethical hacking while serving as a professor and Hacker in Residence at a private university in the Midwestern United States. He currently teaches in one of the top D
Fiche technique
- Titre : Linux Forensics
- Auteur : Polstra, Dr. Philip
- Langue : Anglais
- Format : Broché
- Nombre de pages : 370
- Genre : N/C
- Date de publication : 13-07-2015
- Édition : CreateSpace Independent Publishing Platform
- Poids : 1.06 kg
- Dimensions : 21.59 x 2.1336 x 27.94 cm
- ISBN-10 : 1515037630
- ISBN-13 : 9781515037637
Informations supplémentaires
Ce livre s'est vendu 12 fois sur les 90 derniers jours. Il y a actuellement 5 annonces en vente sur internet à travers le monde. Ce livre est actuellement n°N/C au classement des meilleures ventes d'une selection de places de marché.
Vous souhaitez vendre ce livre ?
C'est simple et rapide, il vous suffit de scanner le code-barres. Cette référence a été scannée 1 fois avec notre app par notre communauté de vendeurs, rejoignez le mouvement en cliquant ici.
Pour finir de vous convaincre
À La Bourse aux Livres, nous proposons les meilleurs prix du marché d'occasion afin de permettre à chacun d’accéder à la lecture. L’état des livres que nous vendons est scrupuleusement vérifié afin de vous garantir un ouvrage de qualité. Acheter ses livres d’occasion, c’est leur offrir une seconde vie tout en faisant des économies.