Digital Forensics with Open Source Tools

4.27 avg rating
( 55 ratings by Goodreads )
 
9781597495868: Digital Forensics with Open Source Tools
View all copies of this ISBN edition:
 
 

Digital Forensics with Open Source Tools is the definitive book on investigating and analyzing computer systems and media using open source tools. The book is a technical procedural guide, and explains the use of open source tools on Mac, Linux and Windows systems as a platform for performing computer forensics. Both well-known and novel forensic methods are demonstrated using command-line and graphical open source computer forensic tools for examining a wide range of target systems and artifacts.

Written by world-renowned forensic practitioners, this book uses the most current examination and analysis techniques in the field. It consists of 9 chapters that cover a range of topics such as the open source examination platform; disk and file system analysis; Windows systems and artifacts; Linux systems and artifacts; Mac OS X systems and artifacts; Internet artifacts; and automating analysis and extending capabilities. The book lends itself to use by students and those entering the field who do not have means to purchase new tools for different investigations.

This book will appeal to forensic practitioners from areas including incident response teams and computer forensic investigators; forensic technicians from legal, audit, and consulting firms; and law enforcement agencies.

    • Written by world-renowned forensic practitioners
    • Details core concepts and techniques of forensic file system analysis
    • Covers analysis of artifacts from the Windows, Mac, and Linux operating systems

    "synopsis" may belong to another edition of this title.

    About the Author:

    Cory Altheide is a Security Engineer at Google, focused on forensics and incident response. Prior to returning to Google, Cory was a principal consultant with MANDIANT, an information security consulting firm that works with the Fortune 500, the defense industrial base and the banks of the world to secure their networks and combat cyber-crime. In this role he responded to numerous incidents for a variety of clients. Cory has authored several papers for the computer forensics journal Digital Investigation and was a contributing author for UNIX and Linux Forensic Analysis (2008) & The Handbook Of Digital Forensics and Investigation (2010). Additionally, Cory is a recurring member of the program committee of the Digital Forensics Research Workshop (DFRWS).

    Mr. Carvey is a digital forensics and incident response analyst with past experience in vulnerability assessments, as well as some limited pen testing. He conducts research into digital forensic analysis of Window systems, identifying and parsing various digital artifacts from those systems, and has developed several innovative tools and investigative processes specific to the digital forensics analysis field. He is the developer of RegRipper, a widely-used tool for Windows Registry parsing and analysis. Mr. Carvey has developed and taught several courses, including Windows Forensics, Registry, and Timeline Analysis.

    Review:

    "This is highly detailed material. Although the introductory chapter adopts an easy pace, with overviews of important technical concepts, most of the other chapters get right down to the practice of forensic analysis. This is not a book you’re going to want to read in bed: you’ll want this right next to a computer – preferably two or three computers running different operating systems – so that you can try the techniques for yourself as you work your way through. The authors admit that this book does not cover everything you need to know. For instance, it focuses entirely on ‘dead drive’ forensics – offline systems. Analysing running systems often requires high-level proprietary tools. But it does give an excellent grounding in the methods of digital forensic analysis and provides a valuable first step in learning the technicalities."--Network Security, May 2012, page 4

    "Digital Forensics – MacGyver Style! The practical solutions of this book, Digital Forensics with Open Source Tools, save the day when commercial tools fail. During an incident, the clock ticks. Response teams scramble to pull anything together to solve the immediate challenge. Cory Altheide and Harlan Carvey take you through the tools and tactics that you need – the ones that in a pinch will get the job done. A welcome addition to my library."--Rob Lee, SANS Institute

    "Intended for students and new computer professionals, or those new to open source applications, this guide to digital forensics provides practical instructions for many common tasks in data recovery and analysis using open source tools. Beginning with a discussion of setting up an open source examination platform and tool set, the work covers disk and file system analysis, Windows, GNU/Linux and Mac OS X systems and artifacts, Internet artifacts, file analysis and automated analysis. The volume includes numerous code examples and tips and tricks as well as an appendix of software tools."--Reference and Research Book News

    "Intended for students and new computer professionals, or those new to open source applications, this guide to digital forensics provides practical instructions for many common tasks in data recovery and analysis using open source tools. Beginning with a discussion of setting up an open source examination platform and tool set, the work covers disk and file system analysis, Windows, GNU/Linux and Mac OS X systems and artifacts, Internet artifacts, file analysis and automated analysis. The volume includes numerous code examples and tips and tricks as well as an appendix of software tools. Chapter examples assume a basic knowledge of the Linux command line interface."--Reference and Research Book News

    "The authors intended this book for two types of readers: complete novices in the world of digital forensics, and seasoned practitioners who are interested in learning more about open source tools that could help them in their work. And although it might seem difficult to merge the knowledge in such a way to make for an interesting book for both groups, in my opinion, the writers managed to do it beautifully."--Net-Security.org

    "About this title" may belong to another edition of this title.

    Buy New View Book
    List Price: US$ 59.95
    US$ 47.30

    Convert currency

    Shipping: FREE
    From United Kingdom to U.S.A.

    Destination, rates & speeds

    Add to Basket

    Top Search Results from the AbeBooks Marketplace

    1.

    Cory Altheide, Harlan Carvey
    Published by Syngress Media,U.S., United States (2011)
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Paperback First Edition Quantity Available: 1
    Seller:
    Book Depository International
    (London, United Kingdom)
    Rating
    [?]

    Book Description Syngress Media,U.S., United States, 2011. Paperback. Condition: New. 1st ed.. Language: English. Brand new Book. Digital Forensics with Open Source Tools is the definitive book on investigating and analyzing computer systems and media using open source tools. The book is a technical procedural guide, and explains the use of open source tools on Mac, Linux and Windows systems as a platform for performing computer forensics. Both well-known and novel forensic methods are demonstrated using command-line and graphical open source computer forensic tools for examining a wide range of target systems and artifacts. Written by world-renowned forensic practitioners, this book uses the most current examination and analysis techniques in the field. It consists of 9 chapters that cover a range of topics such as the open source examination platform; disk and file system analysis; Windows systems and artifacts; Linux systems and artifacts; Mac OS X systems and artifacts; Internet artifacts; and automating analysis and extending capabilities. The book lends itself to use by students and those entering the field who do not have means to purchase new tools for different investigations. This book will appeal to forensic practitioners from areas including incident response teams and computer forensic investigators; forensic technicians from legal, audit, and consulting firms; and law enforcement agencies. Seller Inventory # AA59781597495868

    More information about this seller | Contact this seller

    Buy New
    US$ 47.30
    Convert currency

    Add to Basket

    Shipping: FREE
    From United Kingdom to U.S.A.
    Destination, rates & speeds

    2.

    Cory Altheide, Harlan Carvey
    Published by Syngress Media,U.S., United States (2011)
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Paperback First Edition Quantity Available: 1
    Seller:
    The Book Depository
    (London, United Kingdom)
    Rating
    [?]

    Book Description Syngress Media,U.S., United States, 2011. Paperback. Condition: New. 1st ed.. Language: English. Brand new Book. Digital Forensics with Open Source Tools is the definitive book on investigating and analyzing computer systems and media using open source tools. The book is a technical procedural guide, and explains the use of open source tools on Mac, Linux and Windows systems as a platform for performing computer forensics. Both well-known and novel forensic methods are demonstrated using command-line and graphical open source computer forensic tools for examining a wide range of target systems and artifacts. Written by world-renowned forensic practitioners, this book uses the most current examination and analysis techniques in the field. It consists of 9 chapters that cover a range of topics such as the open source examination platform; disk and file system analysis; Windows systems and artifacts; Linux systems and artifacts; Mac OS X systems and artifacts; Internet artifacts; and automating analysis and extending capabilities. The book lends itself to use by students and those entering the field who do not have means to purchase new tools for different investigations. This book will appeal to forensic practitioners from areas including incident response teams and computer forensic investigators; forensic technicians from legal, audit, and consulting firms; and law enforcement agencies. Seller Inventory # AA59781597495868

    More information about this seller | Contact this seller

    Buy New
    US$ 48.81
    Convert currency

    Add to Basket

    Shipping: FREE
    From United Kingdom to U.S.A.
    Destination, rates & speeds

    3.

    Altheide, Cory; Carvey, Harlan
    Published by Syngress (2011)
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Paperback Quantity Available: 1
    Seller:
    Media Neat
    (Des Plaines, IL, U.S.A.)
    Rating
    [?]

    Book Description Syngress, 2011. Paperback. Condition: New. Brand New, Gift conditionWe Ship Every Day! Free Tracking Number Included! International Buyers Are Welcome! Satisfaction Guaranteed!. Seller Inventory # 40676584516t

    More information about this seller | Contact this seller

    Buy New
    US$ 45.60
    Convert currency

    Add to Basket

    Shipping: US$ 3.99
    Within U.S.A.
    Destination, rates & speeds

    4.

    Altheide, Cory
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Quantity Available: > 20
    Seller:
    Paperbackshop-US
    (Wood Dale, IL, U.S.A.)
    Rating
    [?]

    Book Description 2011. PAP. Condition: New. New Book. Shipped from US within 10 to 14 business days. Established seller since 2000. Seller Inventory # TE-9781597495868

    More information about this seller | Contact this seller

    Buy New
    US$ 46.53
    Convert currency

    Add to Basket

    Shipping: US$ 3.99
    Within U.S.A.
    Destination, rates & speeds

    5.

    Cory Altheide, Harlan Carvey
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Paperback Quantity Available: 1
    Seller:
    Ria Christie Collections
    (Uxbridge, United Kingdom)
    Rating
    [?]

    Book Description Paperback. Condition: New. Not Signed; Digital Forensics with Open Source Tools is the definitive book on investigating and analyzing computer systems and media using open source tools. The book is a technical procedural guide, and explains the use of open source tools on Mac, Linux and Windows systems as a platform for performing comput. book. Seller Inventory # ria9781597495868_rkm

    More information about this seller | Contact this seller

    Buy New
    US$ 50.21
    Convert currency

    Add to Basket

    Shipping: US$ 5.06
    From United Kingdom to U.S.A.
    Destination, rates & speeds

    6.

    Altheide, Cory; Carvey, Harlan
    Published by Syngress
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New PAPERBACK Quantity Available: 3
    Seller:
    WFL
    (Holtsville, NY, U.S.A.)
    Rating
    [?]

    Book Description Syngress. PAPERBACK. Condition: New. 1597495867 Brand New ,Original Book , Direct from Source , Express 6-8 business days worldwide delivery. Seller Inventory # DG#IM266203

    More information about this seller | Contact this seller

    Buy New
    US$ 50.48
    Convert currency

    Add to Basket

    Shipping: US$ 4.90
    Within U.S.A.
    Destination, rates & speeds

    7.

    Cory Altheide
    Published by Syngress Media,U.S.
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Paperback Quantity Available: 1
    Seller:
    THE SAINT BOOKSTORE
    (Southport, United Kingdom)
    Rating
    [?]

    Book Description Syngress Media,U.S. Paperback. Condition: New. New copy - Usually dispatched within 2 working days. Seller Inventory # B9781597495868

    More information about this seller | Contact this seller

    Buy New
    US$ 47.13
    Convert currency

    Add to Basket

    Shipping: US$ 9.07
    From United Kingdom to U.S.A.
    Destination, rates & speeds

    8.

    Altheide, Cory; Carvey, Harlan
    Published by Syngress
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New PAPERBACK Quantity Available: 1
    Seller:
    WFL
    (Holtsville, NY, U.S.A.)
    Rating
    [?]

    Book Description Syngress. PAPERBACK. Condition: New. 1597495867 Brand New ,Original Book , Direct from Source , Express 6-8 business days worldwide delivery. Seller Inventory # RB#BH137630

    More information about this seller | Contact this seller

    Buy New
    US$ 54.96
    Convert currency

    Add to Basket

    Shipping: US$ 4.90
    Within U.S.A.
    Destination, rates & speeds

    9.

    Altheide, Cory
    Published by Syngress (2011)
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Quantity Available: 1
    Seller:
    Books2Anywhere
    (Fairford, GLOS, United Kingdom)
    Rating
    [?]

    Book Description Syngress, 2011. PAP. Condition: New. New Book. Shipped from UK in 4 to 14 days. Established seller since 2000. Seller Inventory # BB-9781597495868

    More information about this seller | Contact this seller

    Buy New
    US$ 48.75
    Convert currency

    Add to Basket

    Shipping: US$ 11.77
    From United Kingdom to U.S.A.
    Destination, rates & speeds

    10.

    Altheide, Cory; Carvey, Harlan
    Published by Syngress Media,U.S. (2011)
    ISBN 10: 1597495867 ISBN 13: 9781597495868
    New Softcover First Edition Quantity Available: 1
    Rating
    [?]

    Book Description Syngress Media,U.S., 2011. Condition: New. 2011. 1st Edition. Paperback. Focuses on investigating and analyzing computer systems and media using open source tools. This book explains the use of these tools on Linux and Windows systems as a platform for performing computer forensics. It details core concepts and techniques of forensic file system analysis. Num Pages: 288 pages, 1, black & white illustrations. BIC Classification: JKVF; UR. Category: (P) Professional & Vocational. Dimension: 232 x 189 x 17. Weight in Grams: 538. . . . . . . Seller Inventory # V9781597495868

    More information about this seller | Contact this seller

    Buy New
    US$ 61.64
    Convert currency

    Add to Basket

    Shipping: FREE
    From Ireland to U.S.A.
    Destination, rates & speeds

    There are more copies of this book

    View all search results for this book