TY - BOOK AU - Johansen, Gerard TI - Digital forensics and incident response: incident response tools and techniques for effective cyber threat response SN - 9781838649005 AV - HV 6773 .J64 2020 PY - 2020/// CY - Birmingham, UK PB - Packt Publishing, Limited KW - COMPUTER CRIMES -- INVESTIGATION N1 - Includes index; Understanding Incident Response -- Managing Cyber Incidents -- Fundamentals of Digital Forensics -- Collecting Network Evidence -- Acquiring Host-Based Evidence -- Forensic Imaging -- Analyzing Network Evidence -- Analyzing System Memory -- Analyzing System Storage -- Analyzing Log Files -- Writing the Incident Report -- Malware Analysis for Incident Response -- Leveraging Threat Intelligence -- Hunting for Threats -- Appendix N2 - After focusing on the fundamentals of incident response that are critical to any information security team, you'll move on to exploring the incident response framework. From understanding its importance to creating a swift and effective response to security incidents, the book will guide you with the help of useful examples. You'll later get up to speed with digital forensic techniques, from acquiring evidence and examining volatile memory through to hard drive examination and network-based evidence. As you progress, you'll discover the role that threat intelligence plays in the incident response process. You'll also learn how to prepare an incident response report that documents the findings of your analysis. Finally, in addition to various incident response activities, the book will address malware analysis, and demonstrate how you can proactively use your digital forensic skills in threat hunting ER -