Digital Forensics and Incident Response - Third Edition: Incident response tools and techniques for effective cyber threat response

Johansen, Gerard

  • 出版商: Packt Publishing
  • 出版日期: 2022-12-16
  • 售價: $2,060
  • 貴賓價: 9.5$1,957
  • 語言: 英文
  • 頁數: 532
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1803238674
  • ISBN-13: 9781803238678
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

商品描述

Build your organization's cyber defense system by effectively applying digital forensics, incident management, and investigation techniques to real-world cyber threats


Key Features:

  • Create a solid incident response framework and manage cyber incidents effectively
  • Learn to apply digital forensics tools and techniques to investigate cyber threats
  • Explore the real-world threat of ransomware and apply proper incident response techniques for investigation and recovery


Book Description:

An understanding of how digital forensics integrates with the overall response to cybersecurity incidents is key to securing your organization's infrastructure from attacks. This updated third edition will help you perform cutting-edge digital forensic activities and incident response with a new focus on responding to ransomware attacks.

After covering the fundamentals of incident response that are critical to any information security team, you'll explore incident response frameworks. From understanding their importance to creating a swift and effective response to security incidents, the book will guide you using examples. Later, you'll cover digital forensic techniques, from acquiring evidence and examining volatile memory through to hard drive examination and network-based evidence. You'll be able to apply these techniques to the current threat of ransomware. As you progress, you'll discover the role that threat intelligence plays in the incident response process. You'll also learn how to prepare an incident response report that documents the findings of your analysis. Finally, in addition to various incident response activities, the book will address malware analysis and demonstrate how you can proactively use your digital forensic skills in threat hunting.

By the end of this book, you'll be able to investigate and report unwanted security breaches and incidents in your organization.


What You Will Learn:

  • Create and deploy an incident response capability within your own organization
  • Perform proper evidence acquisition and handling
  • Analyze the evidence collected and determine the root cause of a security incident
  • Integrate digital forensic techniques and procedures into the overall incident response process
  • Understand different techniques for threat hunting
  • Write incident reports that document the key findings of your analysis
  • Apply incident response practices to ransomware attacks
  • Leverage cyber threat intelligence to augment digital forensics findings


Who this book is for:

This book is for cybersecurity and information security professionals who want to implement digital forensics and incident response in their organizations. You'll also find the book helpful if you're new to the concept of digital forensics and looking to get started with the fundamentals. A basic understanding of operating systems and some knowledge of networking fundamentals are required to get started with this book.

商品描述(中文翻譯)

透過有效應用數位取證、事件管理和調查技術來構建組織的網路防禦系統,以應對真實世界的網路威脅。

主要特點:
- 建立堅實的事件回應框架,有效管理網路事件
- 學習應用數位取證工具和技術來調查網路威脅
- 探索勒索軟體的真實威脅,並應用適當的事件回應技術進行調查和恢復

書籍描述:
了解數位取證如何與整體網路安全事件回應相結合,對於保護組織基礎設施免受攻擊至關重要。本更新的第三版將幫助您進行尖端的數位取證活動和事件回應,並專注於應對勒索軟體攻擊。

在介紹對任何資訊安全團隊至關重要的事件回應基礎知識後,您將探索事件回應框架。從了解其重要性到創建迅速有效的安全事件回應,本書將通過實例指導您。接下來,您將學習數位取證技術,從證據收集和檢查易失性記憶體,到硬碟檢查和基於網路的證據。您將能夠應用這些技術來應對當前的勒索軟體威脅。隨著進展,您將了解威脅情報在事件回應過程中的角色。您還將學習如何準備一份事件回應報告,記錄分析結果。最後,除了各種事件回應活動外,本書還將介紹惡意軟體分析,並展示如何主動運用數位取證技能進行威脅狩獵。

通過閱讀本書,您將能夠調查並報告組織中不需要的安全漏洞和事件。

您將學到什麼:
- 在組織內建立並部署事件回應能力
- 執行正確的證據收集和處理
- 分析收集的證據,確定安全事件的根本原因
- 將數位取證技術和程序整合到整體事件回應過程中
- 了解不同的威脅狩獵技術
- 撰寫事件報告,記錄分析的關鍵發現
- 將事件回應實踐應用於勒索軟體攻擊
- 利用網路威脅情報增強數位取證結果

本書適合對於在組織中實施數位取證和事件回應的資訊安全專業人員。如果您對數位取證的概念尚不熟悉並希望從基礎開始,本書也將對您有所幫助。開始閱讀本書需要基本的作業系統知識和一些網路基礎知識。