000 01633nam a2200229Ia 4500
003 NULRC
005 20250520103030.0
008 250520s9999 xx 000 0 und d
020 _a9781718501966
040 _cNULRC
050 _aHV 8079.C65 .N55 2022
100 _aNikkel, Bruce
_eauthor
245 0 _aPractical linux forensics :
_ba guide for digital investigators /
_cBruce Nikkel
260 _aSan Francisco, California :
_bNo Starch Press, Inc.,
_cc2022
300 _axxx, 368 pages ;
_c24 cm.
365 _bUSD26
504 _aIncludes index.
505 _aDigital forensics overview -- Linux overview -- Extracting evidence from storage devices and filesystems -- Directory layout and forensic analysis of Linux files -- Investigating evidence from Linux log -- Reconstructing system boot and initialization -- Examination of installed software packages -- Identifying network configuration artifacts -- Forensic analysis of time and location -- Reconstructing user desktops and login activity -- Forensic traces of attached peripheral devices -- Closing remarks -- File and directory list for digital investigators.
520 _aA thorough resource for forensic investigators, this book covers a variety of methods and techniques for locating and analyzing digital evidence found on modern Linux systems after a security incident or cyberattack. Readers will learn how Linux works from a digital forensics and investigation perspective and how to interpret evidence using tool-independent techniques relevant to any forensic analysis platform.
650 _aDIGITAL FORENSIC SCIENCE
942 _2lcc
_cBK
999 _c21839
_d21839