Digital Forensics & Incident Response: A CEH Professional’s Field Guide
- Practical Techniques for Evidence Collection, Analysis, and Cyber Incident Management
- About the Author
- Preface
- Chapter 1: Introduction to DFIR
- Chapter 2: Legal Framework and Chain of Custody
- Chapter 3: Evidence Acquisition
- Chapter 4: Disk Forensics with Autopsy and FTK
- Chapter 5: Memory Forensics with Volatility 3
- Chapter 6: Network Forensics
- Chapter 7: Log Analysis and SIEM Forensics
- Chapter 8: Malware Analysis Overview
- Chapter 9: Incident Response Lifecycle
- Chapter 10: Threat Hunting
- Chapter 11: Digital Forensics Reporting
- Chapter 12: Lab Setup for DFIR Practice
- Appendix A: Quick Reference — Windows Event IDs
- Appendix B: Volatility 3 Plugin Quick Reference
- Appendix C: Essential DFIR Tool Commands
- Closing Thoughts
Lists
- Numbered Lists
- Bulleted Lists
- Definition Lists
About These Chapters
- Read on…
Book Resources
Tables
Code Blocks
Images
YouTube Videos
Math Blocks
Asides and Blurbs
- Read on…
External Resources
Including a Code File
Other External Types
- Read on…
Cross-references
Linking to a Heading
Linking to a Figure or Table
Choosing What the Link Shows
- Read on…
Footnotes and Endnotes
Inserting a Note
Editing a Note
Note IDs
- Read on…
Indexing Your Book
Entries and Sub-entries
Viewing Your Index
Previewing and Publishing
- Previewing Your Book
- Publishing Your Book
This Is A Book
- Read on…