- Digital Forensics and Incident Response
- Gerard Johansen
- 143字
- 2021-07-02 18:49:47
Examination
The examination phase details the specific tools and forensic techniques that are utilized to discover and extract data from the evidence that is seized as part of the incident. For example, in a case where malware is suspected of infecting a desktop system as part of a larger attack, the extraction of specific information from an acquired memory image would take part in this stage. In other cases, digital forensic examiners may need to extract Secure Shell (SSH) traffic from a network capture. The examination of digital evidence also continues the process of proper preservation in that examiners maintain the utmost care with the evidence during the examination. If the digital forensic examiner does not take care in the preservation of the evidence in this stage, there is the possibility of contamination that would result in the evidence being unreliable or unusable.
- Boost.Asio C++ Network Programming(Second Edition)
- AngularJS入門與進階
- 程序員修煉之道:程序設計入門30講
- Python 3.7網絡爬蟲快速入門
- Learn to Create WordPress Themes by Building 5 Projects
- Spring Cloud、Nginx高并發核心編程
- C語言程序設計實踐教程
- Python Web數據分析可視化:基于Django框架的開發實戰
- OpenGL Data Visualization Cookbook
- 關系數據庫與SQL Server 2012(第3版)
- Mastering JavaScript Promises
- Java EE互聯網輕量級框架整合開發:SSM+Redis+Spring微服務(上下冊)
- 歐姆龍PLC編程指令與梯形圖快速入門
- Learning Zimbra Server Essentials
- 編程真好玩:從零開始學網頁設計及3D編程