- Digital Forensics and Incident Response
- Gerard Johansen
- 131字
- 2021-07-02 18:49:47
Analysis
Once the Examination phase has extracted the potentially relevant pieces of data, the digital forensic examiner then analyzes the data in light of any other relevant data obtained. For example, if the digital forensic analyst has discovered that a compromised host has on open connection to an external IP address, they would then correlate that information with an analysis of the packet capture taken from the network. Using the IP address as a starting point, the analyst would be able to isolate the particular traffic. From here, the analyst may be able to determine that the compromised host is sending out a beacon to a C2 server. From here, using additional sources, the analyst may be able to determine what the particular attack vector is tied with that IP address.
- 程序員修煉之道:程序設(shè)計(jì)入門30講
- Android Jetpack開發(fā):原理解析與應(yīng)用實(shí)戰(zhàn)
- 摩登創(chuàng)客:與智能手機(jī)和平板電腦共舞
- SpringMVC+MyBatis快速開發(fā)與項(xiàng)目實(shí)戰(zhàn)
- 數(shù)據(jù)庫(kù)系統(tǒng)原理及MySQL應(yīng)用教程
- Java面向?qū)ο蟪绦蜷_發(fā)及實(shí)戰(zhàn)
- 從Excel到Python:用Python輕松處理Excel數(shù)據(jù)(第2版)
- Flutter跨平臺(tái)開發(fā)入門與實(shí)戰(zhàn)
- “笨辦法”學(xué)C語(yǔ)言
- 軟件項(xiàng)目管理實(shí)用教程
- Python入門很輕松(微課超值版)
- Visual C++程序設(shè)計(jì)與項(xiàng)目實(shí)踐
- Docker:容器與容器云(第2版)
- TypeScript全棧開發(fā)
- Elasticsearch搜索引擎構(gòu)建入門與實(shí)戰(zhàn)