Bookbot

Practical Forensic Imaging

Securing Digital Evidence with Linux Tools

Parametry

  • 324 strony
  • 12 godzin czytania

Więcej o książce

Forensic image acquisition is crucial for postmortem incident response and evidence collection. Digital forensic investigators gather, preserve, and manage digital evidence for civil and criminal cases, policy violations, disputes, and cyber attack analyses. This guide offers an in-depth examination of securing and managing digital evidence using Linux-based command line tools. It covers the entire forensic acquisition process and addresses various practical scenarios related to imaging storage media. Key learning points include performing forensic imaging on magnetic hard disks, SSDs, flash drives, optical discs, magnetic tapes, and legacy technologies; protecting evidence media from accidental modification; and managing large forensic image files, including storage capacity, image format conversion, compression, splitting, duplication, secure transfer and disposal. The guide also emphasizes preserving and verifying evidence integrity with cryptographic methods, public key signatures, and timestamping. It explores newer drive technologies like NVME and SATA Express, as well as managing drive security through ATA passwords, encrypted drives, and OS-encrypted systems. Additionally, it addresses acquiring usable images from complex situations such as RAID systems and damaged media. With its focus on digital forensic acquisition and evidence preservation, this resource is invaluable for digital forensic investigators lookin

Zakup książki

Practical Forensic Imaging, Bruce Nikkel

Język
Rok wydania
2016
Oprawa
(miękka)
Jak tylko się pojawi, wyślemy Ci wiadomość e-mail.

Metody płatności

Nikt jeszcze nie ocenił.Oceń

Tytuł
Practical Forensic Imaging
Podtytuł
Securing Digital Evidence with Linux Tools
Język
angielski
Rok wydania
2016
Oprawa
miękka
Liczba stron
324
ISBN10
1593277938
ISBN13
9781593277932
Seria
Opis
Forensic image acquisition is crucial for postmortem incident response and evidence collection. Digital forensic investigators gather, preserve, and manage digital evidence for civil and criminal cases, policy violations, disputes, and cyber attack analyses. This guide offers an in-depth examination of securing and managing digital evidence using Linux-based command line tools. It covers the entire forensic acquisition process and addresses various practical scenarios related to imaging storage media. Key learning points include performing forensic imaging on magnetic hard disks, SSDs, flash drives, optical discs, magnetic tapes, and legacy technologies; protecting evidence media from accidental modification; and managing large forensic image files, including storage capacity, image format conversion, compression, splitting, duplication, secure transfer and disposal. The guide also emphasizes preserving and verifying evidence integrity with cryptographic methods, public key signatures, and timestamping. It explores newer drive technologies like NVME and SATA Express, as well as managing drive security through ATA passwords, encrypted drives, and OS-encrypted systems. Additionally, it addresses acquiring usable images from complex situations such as RAID systems and damaged media. With its focus on digital forensic acquisition and evidence preservation, this resource is invaluable for digital forensic investigators lookin