Digital Forensics with Kali Linux : Enhance your investigation skills by performing network and memory forensics with Kali Linux 2022.x, 3/e (Paperback)
暫譯: Kali Linux 數位鑑識:透過 Kali Linux 2022.x 提升您的調查技能,進行網路與記憶體鑑識,第三版 (平裝本)

Parasram, Shiva V. N.

  • 出版商: Packt Publishing
  • 出版日期: 2023-04-14
  • 售價: $1,680
  • 貴賓價: 9.5$1,596
  • 語言: 英文
  • 頁數: 414
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1837635153
  • ISBN-13: 9781837635153
  • 相關分類: 資訊安全kali-linuxLinux
  • 立即出貨 (庫存=1)

買這商品的人也買了...

相關主題

商品描述

Explore various digital forensics methodologies and frameworks and manage your cyber incidents effectively

Key Features

  • Gain red, blue, and purple team tool insights and understand their link with digital forensics
  • Perform DFIR investigation and get familiarized with Autopsy 4
  • Explore network discovery and forensics tools such as Nmap, Wireshark, Xplico, and Shodan

Book Description

Kali Linux is a Linux-based distribution that's widely used for penetration testing and digital forensics. This third edition is updated with real-world examples and detailed labs to help you take your investigation skills to the next level using powerful tools.

This new edition will help you explore modern techniques for analysis, extraction, and reporting using advanced tools such as FTK Imager, Hex Editor, and Axiom. You'll cover the basics and advanced areas of digital forensics within the world of modern forensics while delving into the domain of operating systems. As you advance through the chapters, you'll explore various formats for file storage, including secret hiding places unseen by the end user or even the operating system. You'll also discover how to install Windows Emulator, Autopsy 4 in Kali, and how to use Nmap and NetDiscover to find device types and hosts on a network, along with creating forensic images of data and maintaining integrity using hashing tools. Finally, you'll cover advanced topics such as autopsies and acquiring investigation data from networks, memory, and operating systems.

By the end of this digital forensics book, you'll have gained hands-on experience in implementing all the pillars of digital forensics: acquisition, extraction, analysis, and presentation – all using Kali Linux's cutting-edge tools.

What you will learn

  • Install Kali Linux on Raspberry Pi 4 and various other platforms
  • Run Windows applications in Kali Linux using Windows Emulator as Wine
  • Recognize the importance of RAM, file systems, data, and cache in DFIR
  • Perform file recovery, data carving, and extraction using Magic Rescue
  • Get to grips with the latest Volatility 3 framework and analyze the memory dump
  • Explore the various ransomware types and discover artifacts for DFIR investigation
  • Perform full DFIR automated analysis with Autopsy 4
  • Become familiar with network forensic analysis tools (NFATs)

Who this book is for

This book is for students, forensic analysts, digital forensics investigators and incident responders, security analysts and administrators, penetration testers, or anyone interested in enhancing their forensics abilities using the latest version of Kali Linux along with powerful automated analysis tools. Basic knowledge of operating systems, computer components, and installation processes will help you gain a better understanding of the concepts covered.

商品描述(中文翻譯)

探索各種數位鑑識方法論和框架,並有效管理您的網路事件

主要特色

- 獲得紅隊、藍隊和紫隊工具的見解,了解它們與數位鑑識的關聯
- 執行 DFIR 調查,熟悉 Autopsy 4
- 探索網路發現和鑑識工具,如 Nmap、Wireshark、Xplico 和 Shodan

書籍描述

Kali Linux 是一個基於 Linux 的發行版,廣泛用於滲透測試和數位鑑識。本書第三版更新了真實世界的範例和詳細的實驗室,幫助您利用強大的工具提升調查技能。

這個新版本將幫助您探索使用先進工具(如 FTK Imager、Hex Editor 和 Axiom)進行分析、提取和報告的現代技術。您將涵蓋數位鑑識的基本和進階領域,深入現代鑑識的世界,同時探討作業系統的領域。隨著您逐步深入各章節,您將探索各種檔案儲存格式,包括終端使用者或甚至作業系統無法見到的秘密隱藏位置。您還將學習如何在 Kali 中安裝 Windows Emulator 和 Autopsy 4,以及如何使用 Nmap 和 NetDiscover 找到網路上的設備類型和主機,並創建數據的鑑識影像,使用哈希工具維護完整性。最後,您將涵蓋進階主題,如解剖檢查和從網路、記憶體和作業系統獲取調查數據。

在這本數位鑑識書籍結束時,您將獲得實踐經驗,實施數位鑑識的所有支柱:獲取、提取、分析和呈現—所有這些都使用 Kali Linux 的尖端工具。

您將學到的內容

- 在 Raspberry Pi 4 和其他各種平台上安裝 Kali Linux
- 使用 Windows Emulator(如 Wine)在 Kali Linux 中運行 Windows 應用程式
- 認識 RAM、檔案系統、數據和快取在 DFIR 中的重要性
- 使用 Magic Rescue 執行檔案恢復、數據雕刻和提取
- 熟悉最新的 Volatility 3 框架並分析記憶體轉儲
- 探索各種勒索病毒類型並發現 DFIR 調查的證據
- 使用 Autopsy 4 執行完整的 DFIR 自動化分析
- 熟悉網路鑑識分析工具(NFATs)

本書適合誰

本書適合學生、鑑識分析師、數位鑑識調查員和事件響應者、安全分析師和管理員、滲透測試者,或任何希望利用最新版本的 Kali Linux 和強大的自動化分析工具提升其鑑識能力的人。對作業系統、計算機組件和安裝過程的基本知識將幫助您更好地理解所涵蓋的概念。

目錄大綱

  1. Red, Blue, and Purple Teaming Fundamentals
  2. Introduction to Digital Forensics
  3. Installing Kali Linux
  4. Additional Kali Installations and Post-Installation Tasks
  5. Installing Wine in Kali Linux
  6. Understanding File Systems and Storage
  7. Incident Response, Data Acquisitions, and DFIR Frameworks
  8. Evidence Acquisition Tools
  9. File Recovery and Data Carving Tools
  10. Memory Forensics and Analysis with Volatility 3
  11. Artifact, Malware, and Ransomware Analysis
  12. Autopsy Forensic Browser
  13. Performing a Full DFIR Analysis with the Autopsy 4 GUI
  14. Network Discovery Tools
  15. Packet Capture Analysis with Xplico
  16. Network Forensic Analysis Tools

目錄大綱(中文翻譯)


  1. Red, Blue, and Purple Teaming Fundamentals

  2. Introduction to Digital Forensics

  3. Installing Kali Linux

  4. Additional Kali Installations and Post-Installation Tasks

  5. Installing Wine in Kali Linux

  6. Understanding File Systems and Storage

  7. Incident Response, Data Acquisitions, and DFIR Frameworks

  8. Evidence Acquisition Tools

  9. File Recovery and Data Carving Tools

  10. Memory Forensics and Analysis with Volatility 3

  11. Artifact, Malware, and Ransomware Analysis

  12. Autopsy Forensic Browser

  13. Performing a Full DFIR Analysis with the Autopsy 4 GUI

  14. Network Discovery Tools

  15. Packet Capture Analysis with Xplico

  16. Network Forensic Analysis Tools