- Digital Forensics and Incident Response
- Gerard Johansen
- 143字
- 2021-07-02 18:49:47
Examination
The examination phase details the specific tools and forensic techniques that are utilized to discover and extract data from the evidence that is seized as part of the incident. For example, in a case where malware is suspected of infecting a desktop system as part of a larger attack, the extraction of specific information from an acquired memory image would take part in this stage. In other cases, digital forensic examiners may need to extract Secure Shell (SSH) traffic from a network capture. The examination of digital evidence also continues the process of proper preservation in that examiners maintain the utmost care with the evidence during the examination. If the digital forensic examiner does not take care in the preservation of the evidence in this stage, there is the possibility of contamination that would result in the evidence being unreliable or unusable.
- Practical Data Analysis Cookbook
- 深入核心的敏捷開發:ThoughtWorks五大關鍵實踐
- vSphere High Performance Cookbook
- CentOS 7 Linux Server Cookbook(Second Edition)
- Blender 3D Incredible Machines
- Java軟件開發基礎
- 利用Python進行數據分析(原書第3版)
- Hands-On Natural Language Processing with Python
- Oracle從入門到精通(第5版)
- Kotlin開發教程(全2冊)
- Mastering OpenStack
- 和孩子一起學編程:用Scratch玩Minecraft我的世界
- 你必須知道的.NET(第2版)
- 用Go語言自制編譯器
- ServiceDesk Plus 8.x Essentials