Digital Forensics with Kali Linux - Third Edition by Shiva V. N. Parasram

Digital Forensics with Kali Linux - Third Edition by Shiva V. N. Parasram

Author:Shiva V. N. Parasram
Language: eng
Format: epub
Publisher: Packt
Published: 2023-11-15T00:00:00+00:00


Summary

If there was only one thing that I’d like you to take away from this chapter, it would be to remember that the original evidence, particularly hard drives, storage media, and RAM images, should only be used to create forensically-sound bitstream copies. The original evidence is never to be worked on.

To recap, when a breach is reported, there should be an established first responder who, as per protocol, performs the tasks of documenting and securing the scene as well as collecting and preserving the evidence. The first responder should have a toolkit with various tools and items for the acquisition of evidence, and when handing over the evidence to other parties, ensure that the CoC is maintained.

Additionally, we looked at the various procedures and best practices when investigating devices that are powered on and powered off, and we discussed the importance of using a write blocker to prevent the original evidence from being tampered with and then using a hashing tool for integrity verification purposes. Finally, I’ve left you with some very useful DFIR frameworks, which, when combined with the SWGDE guidelines, make for an impressive DFIR playbook.

You’ve come this far, and I know it must have been a bit of an information overload, but now we can get to the practical section of this book where we can begin our investigation using digital forensics tools in Kali Linux. Let’s go!



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.