Items related to Linux Forensics

Philip Polstra Linux Forensics ISBN 13: 9781515037637

Linux Forensics - Softcover

  • 4.18 out of 5 stars
    33 ratings by Goodreads
 
9781515037637: Linux Forensics

Synopsis

Linux Forensics is the most comprehensive and up-to-date resource for those wishing to quickly and efficiently perform forensics on Linux systems. It is also a great asset for anyone that would like to better understand Linux internals.

Linux Forensics will guide you step by step through the process of investigating a computer running Linux. Everything you need to know from the moment you receive the call from someone who thinks they have been attacked until the final report is written is covered in this book. All of the tools discussed in this book are free and most are also open source.

Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Linux systems. While readers will have a strong grasp of Python and shell scripting by the time they complete this book, no prior knowledge of either of these scripting languages is assumed. Linux Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images.

Linux Forensics contains extensive coverage of Linux ext2, ext3, and ext4 filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussions of advanced attacks and malware analysis round out the book.

Book Highlights

  • 370 pages in large, easy-to-read 8.5 x 11 inch format
  • Over 9000 lines of Python scripts with explanations
  • Over 800 lines of shell scripts with explanations
  • A 102 page chapter containing up-to-date information on the ext4 filesystem
  • Two scenarios described in detail with images available from the book website
  • All scripts and other support files are available from the book website

Chapter Contents

  1. First Steps
    • General Principles
    • Phases of Investigation
    • High-level Process
    • Building a Toolkit
  2. Determining If There Was an Incident
    • Opening a Case
    • Talking to Users
    • Documenation
    • Mounting Known-good Binaries
    • Minimizing Disturbance to the Subject
    • Automation With Scripting
  3. Live Analysis
    • Getting Metadata
    • Using Spreadsheets
    • Getting Command Histories
    • Getting Logs
    • Using Hashes
    • Dumping RAM
  4. Creating Images
    • Shutting Down the System
    • Image Formats
    • DD
    • DCFLDD
    • Write Blocking
    • Imaging Virtual Machines
    • Imaging Physical Drives
  5. Mounting Images
    • Master Boot Record Based Partions
    • GUID Partition Tables
    • Mounting Partitions In Linux
    • Automating With Python
  6. Analyzing Mounted Images
    • Getting Timestamps
    • Using LibreOffice
    • Using MySQL
    • Creating Timelines
  7. Extended Filesystems
    • Basics
    • Superblocks
    • Features
    • Using Python
    • Finding Things That Are Out Of Place
    • Inodes
    • Journaling
  8. Memory Analysis
    • Volatility
    • Creating Profiles
    • Linux Commands
  9. Dealing With More Advanced Attackers
  10. Malware
    • Is It Malware?
    • Malware Analysis Tools
    • Static Analysis
    • Dynamic Analysis
    • Obfuscation
  11. The Road Ahead
    • Learning More
    • Communities
    • Conferences
    • Certifications

"synopsis" may belong to another edition of this title.

From the Author

Linux Forensics is the most up-to-date and comprehensive book on performing Linux forensics period.  It has been a real labor of love to produce such a complete book.  If you ever think you might need to investigate a Linux system or just want to learn more about how Linux works under the covers, this book is for you.  This book will also have you well on your way to performing forensic investigations of other systems (Windows, OS X) from a Linux forensics workstation.

While there are over 9000 lines of Python and 800 lines of shell script in this book, I make no assumptions about the readers expertise in these scripting languages.  In other words, in addition to being a book on forensics this book is also a good primer on Python and bash scripting.  By the time you finish this book you will know how Linux systems work, how to investigate them, and also how to automate tedious tasks with Python and shell scripts.
The 102 page chapter of current and comprehensive information concerning the ext4 filesystem makes the book a must have all on its own.  The other chapters on live response, filesystem analysis, memory analysis with Volatility, image creation, advanced attacks, and malware further solidify the must-have status of this book.

See for yourself why readers are saying "Dr. Phil covers all the topics in a lot of detail and talks about automating stuff with Python. This is really helpful as this allows to automate a lot of mundane and painful tasks, which would otherwise take a lot of time. I've already recommended this to my colleagues at work and have ordered more now from Amazon for them." - WiFi Hacker

From the Back Cover

A practical guide to performing forensic investigations on Linux systems.
Linux Forensics will guide you step by step through the process of investigating a computer running Linux. Everything you need to know from the moment you receive the call from a client who thinks they have been attacked until the final report is written is covered in this book. All of the tools discussed in this book are free and most are also open source.
Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Linux systems. Linux Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images.
Linux Forensics contains extensive coverage of Linux ext2, ext3, and ext4 filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussions of advanced attacks and malware analysis round out the book.

"About this title" may belong to another edition of this title.

Buy Used

Condition: Very Good
Ship within 24hrs. Satisfaction...
View this item

FREE shipping within U.S.A.

Destination, rates & speeds

Search results for Linux Forensics

Stock Image

Philip Polstra
ISBN 10: 1515037630 ISBN 13: 9781515037637
Used Paperback

Seller: BooksRun, Philadelphia, PA, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Paperback. Condition: Very Good. Ship within 24hrs. Satisfaction 100% guaranteed. APO/FPO addresses supported. Seller Inventory # 1515037630-8-1-42

Contact seller

Buy Used

US$ 14.55
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 2 available

Add to basket

Stock Image

Polstra, Philip
ISBN 10: 1515037630 ISBN 13: 9781515037637
Used Softcover First Edition

Seller: Better World Books: West, Reno, NV, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: As New. 1st Edition. Used book that is in almost brand-new condition. Seller Inventory # 21363108-75

Contact seller

Buy Used

US$ 15.02
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Philip Polstra
ISBN 10: 1515037630 ISBN 13: 9781515037637
Used paperback

Seller: HPB-Red, Dallas, TX, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

paperback. Condition: Good. Connecting readers with great books since 1972! Used textbooks may not include companion materials such as access codes, etc. May have some wear or writing/highlighting. We ship orders daily and Customer Service is our top priority! Seller Inventory # S_404504656

Contact seller

Buy Used

US$ 12.86
Convert currency
Shipping: US$ 3.75
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Stock Image

Philip Polstra
ISBN 10: 1515037630 ISBN 13: 9781515037637
Used Softcover

Seller: SecondSale, Montgomery, IL, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: Good. Item in good condition. Textbooks may not include supplemental items i.e. CDs, access codes etc. Seller Inventory # 00080742545

Contact seller

Buy Used

US$ 16.78
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Seller Image

Polstra, Philip
ISBN 10: 1515037630 ISBN 13: 9781515037637
New Softcover

Seller: GreatBookPrices, Columbia, MD, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: New. Seller Inventory # 24575289-n

Contact seller

Buy New

US$ 48.35
Convert currency
Shipping: US$ 2.64
Within U.S.A.
Destination, rates & speeds

Quantity: Over 20 available

Add to basket

Stock Image

Philip Polstra
ISBN 10: 1515037630 ISBN 13: 9781515037637
New Softcover
Print on Demand

Seller: California Books, Miami, FL, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: New. Print on Demand. Seller Inventory # I-9781515037637

Contact seller

Buy New

US$ 51.00
Convert currency
Shipping: FREE
Within U.S.A.
Destination, rates & speeds

Quantity: Over 20 available

Add to basket

Seller Image

Polstra, Philip
ISBN 10: 1515037630 ISBN 13: 9781515037637
Used Softcover

Seller: GreatBookPrices, Columbia, MD, U.S.A.

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: As New. Unread book in perfect condition. Seller Inventory # 24575289

Contact seller

Buy Used

US$ 54.37
Convert currency
Shipping: US$ 2.64
Within U.S.A.
Destination, rates & speeds

Quantity: Over 20 available

Add to basket

Seller Image

Polstra, Philip
ISBN 10: 1515037630 ISBN 13: 9781515037637
Used Soft cover

Seller: Hanselled Books, Burntisland, FIFE, United Kingdom

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Soft cover. Condition: Very Good. P/b 345 pages, condition is very good. Linux Forensics is the most comprehensive and up-to-date resource for those wishing to quickly and efficiently perform forensics on Linux systems. It is also a great asset for anyone that would like to better understand Linux internals. Linux Forensics will guide you step by step through the process of investigating a computer running Linux. Everything you need to know from the moment you receive the call from someone who thinks they have been attacked until the final report is written is covered in this book. All of the tools discussed in this book are free and most are also open source. Seller Inventory # 63799

Contact seller

Buy Used

US$ 37.85
Convert currency
Shipping: US$ 22.71
From United Kingdom to U.S.A.
Destination, rates & speeds

Quantity: 1 available

Add to basket

Seller Image

Polstra, Philip
ISBN 10: 1515037630 ISBN 13: 9781515037637
New Softcover

Seller: GreatBookPricesUK, Woodford Green, United Kingdom

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: New. Seller Inventory # 24575289-n

Contact seller

Buy New

US$ 64.39
Convert currency
Shipping: US$ 20.04
From United Kingdom to U.S.A.
Destination, rates & speeds

Quantity: Over 20 available

Add to basket

Seller Image

Polstra, Philip
ISBN 10: 1515037630 ISBN 13: 9781515037637
Used Softcover

Seller: GreatBookPricesUK, Woodford Green, United Kingdom

Seller rating 5 out of 5 stars 5-star rating, Learn more about seller ratings

Condition: As New. Unread book in perfect condition. Seller Inventory # 24575289

Contact seller

Buy Used

US$ 66.10
Convert currency
Shipping: US$ 20.04
From United Kingdom to U.S.A.
Destination, rates & speeds

Quantity: Over 20 available

Add to basket

There are 2 more copies of this book

View all search results for this book