Cloud Forensics Demystified: Decoding cloud investigation complexities for digital forensic professionals
暫譯: 雲端取證解密:為數位取證專業人士解讀雲端調查的複雜性
Ramakrishnan, Ganesh, Haqanee, Mansoor
- 出版商: Packt Publishing
- 出版日期: 2024-02-22
- 售價: $1,880
- 貴賓價: 9.5 折 $1,786
- 語言: 英文
- 頁數: 384
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1800564414
- ISBN-13: 9781800564411
-
相關分類:
Kubernetes、資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
Enhance your skills as a cloud investigator to adeptly respond to cloud incidents by combining traditional forensic techniques with innovative approaches
Key Features:
- Uncover the steps involved in cloud forensic investigations for M365 and Google Workspace
- Explore tools and logs available within AWS, Azure, and Google for cloud investigations
- Learn how to investigate containerized services such as Kubernetes and Docker
- Purchase of the print or Kindle book includes a free PDF eBook
Book Description:
As organizations embrace cloud-centric environments, it becomes imperative for security professionals to master the skills of effective cloud investigation. Cloud Forensics Demystified addresses this pressing need, explaining how to use cloud-native tools and logs together with traditional digital forensic techniques for a thorough cloud investigation.
The book begins by giving you an overview of cloud services, followed by a detailed exploration of the tools and techniques used to investigate popular cloud platforms such as Amazon Web Services (AWS), Azure, and Google Cloud Platform (GCP). Progressing through the chapters, you'll learn how to investigate Microsoft 365, Google Workspace, and containerized environments such as Kubernetes. Throughout, the chapters emphasize the significance of the cloud, explaining which tools and logs need to be enabled for investigative purposes and demonstrating how to integrate them with traditional digital forensic tools and techniques to respond to cloud security incidents.
By the end of this book, you'll be well-equipped to handle security breaches in cloud-based environments and have a comprehensive understanding of the essential cloud-based logs vital to your investigations. This knowledge will enable you to swiftly acquire and scrutinize artifacts of interest in cloud security incidents.
What You Will Learn:
- Explore the essential tools and logs for your cloud investigation
- Master the overall incident response process and approach
- Familiarize yourself with the MITRE ATT&CK framework for the cloud
- Get to grips with live forensic analysis and threat hunting in the cloud
- Learn about cloud evidence acquisition for offline analysis
- Analyze compromised Kubernetes containers
- Employ automated tools to collect logs from M365
Who this book is for:
This book is for cybersecurity professionals, incident responders, and IT professionals adapting to the paradigm shift toward cloud-centric environments. Anyone seeking a comprehensive guide to investigating security incidents in popular cloud platforms such as AWS, Azure, and GCP, as well as Microsoft 365, Google Workspace, and containerized environments like Kubernetes will find this book useful. Whether you're a seasoned professional or a newcomer to cloud security, this book offers insights and practical knowledge to enable you to handle and secure cloud-based infrastructure.
商品描述(中文翻譯)
強化您作為雲端調查員的技能,靈活應對雲端事件,結合傳統的取證技術與創新的方法
主要特點:
- 揭示 M365 和 Google Workspace 雲端取證調查的步驟
- 探索 AWS、Azure 和 Google 中可用於雲端調查的工具和日誌
- 學習如何調查容器化服務,如 Kubernetes 和 Docker
- 購買印刷版或 Kindle 書籍可獲得免費 PDF 電子書
書籍描述:
隨著組織採用以雲為中心的環境,安全專業人員掌握有效雲端調查的技能變得至關重要。《雲端取證解密》針對這一迫切需求,解釋如何將雲原生工具和日誌與傳統數位取證技術結合,以進行徹底的雲端調查。
本書首先概述雲端服務,接著詳細探討用於調查流行雲端平台(如 Amazon Web Services (AWS)、Azure 和 Google Cloud Platform (GCP))的工具和技術。隨著章節的進展,您將學習如何調查 Microsoft 365、Google Workspace 以及像 Kubernetes 這樣的容器化環境。整個過程中,章節強調雲端的重要性,解釋哪些工具和日誌需要啟用以便進行調查,並展示如何將它們與傳統數位取證工具和技術整合,以應對雲端安全事件。
在本書結束時,您將能夠妥善處理雲端環境中的安全漏洞,並全面了解對於調查至關重要的雲端日誌。這些知識將使您能夠迅速獲取和檢查雲端安全事件中的相關證據。
您將學到的內容:
- 探索雲端調查的基本工具和日誌
- 精通整體事件響應過程和方法
- 熟悉雲端的 MITRE ATT&CK 框架
- 理解雲端中的即時取證分析和威脅獵捕
- 學習雲端證據獲取以進行離線分析
- 分析被攻擊的 Kubernetes 容器
- 使用自動化工具從 M365 收集日誌
本書適合對象:
本書適合網路安全專業人員、事件響應者以及適應向雲端為中心環境轉變的 IT 專業人員。任何尋求全面指南以調查流行雲端平台(如 AWS、Azure 和 GCP)以及 Microsoft 365、Google Workspace 和像 Kubernetes 這樣的容器化環境中的安全事件的人,都會發現本書非常有用。無論您是資深專業人士還是雲端安全的新手,本書提供的見解和實用知識將使您能夠處理和保護雲端基礎設施。