Practical Linux Forensics dives into the details of analyzing postmortem images of Linux systems that were misused, abused, or attacked. You'll learn how to locate and interpret digital evidence on Linux desktops, servers, and IoT devices, and reconstruct a timeline of events after a crime or security incident. Following an overview of the Linux operating system, you'll learn how to analyze storage, filesystems, and installed software, as well as package management systems from a range of distributions. You'll investigate syslog, the systemd journal, kernel and audit logs, and daemon and application logs. In addition, you'll inspect network configurations including interfaces, addresses, network managers, DNS, wireless artifacts, VPNs, firewalls, and proxy settings. You'll also learn how to: Examine settings for time, locale, language, and keyboard, as well as timelines and geolocation, Reconstruct the Linux startup process, from system boot and kernel initialization to the login screen, Analyze partition tables, volume management, filesystems, directory layout, installed software, and network configuration, Perform historical analysis of power, temperature, and physical environment, as well as shutdowns, reboots, and crashes, Investigate user login sessions and identify traces of attached peripherals including disks, printers, and other external devices, This comprehensive guide is platform- and tool-agnostic and written for investigators with varying Linux skill levels. Begin your digital forensics journey here. Book jacket.
- ISBN:
- 9781718501966
- 9781718501966
-
Category:
- Computer security
- Format:
- Paperback
- Publication Date:
-
07-12-2021
- Language:
- English
- Publisher:
- No Starch Press, Incorporated
- Country of origin:
- United States
- Dimensions (mm):
- 233x180x28mm
- Weight:
- 0.79kg
This title is in stock with our overseas supplier and should arrive at our Sydney warehouse within 1 - 2 weeks of you placing an order.
Once received into our warehouse we will despatch it to you with a Shipping Notification which includes online tracking.
Please check the estimated delivery times below for your region, for after your order is despatched from our warehouse:
ACT Metro: 2 working days
NSW Metro: 2 working days
NSW Rural: 2-3 working days
NSW Remote: 2-5 working days
NT Metro: 3-6 working days
NT Remote: 4-10 working days
QLD Metro: 2-4 working days
QLD Rural: 2-5 working days
QLD Remote: 2-7 working days
SA Metro: 2-5 working days
SA Rural: 3-6 working days
SA Remote: 3-7 working days
TAS Metro: 3-6 working days
TAS Rural: 3-6 working days
VIC Metro: 2-3 working days
VIC Rural: 2-4 working days
VIC Remote: 2-5 working days
WA Metro: 3-6 working days
WA Rural: 4-8 working days
WA Remote: 4-12 working days
Share This Book: