Linux Forensics (Paperback)
Philip Polstra
Sold by CitiRetail, Stevenage, United Kingdom
AbeBooks Seller since 29 June 2022
New - Soft cover
Condition: New
Ships from United Kingdom to U.S.A.
Quantity: 1 available
Add to basketSold by CitiRetail, Stevenage, United Kingdom
AbeBooks Seller since 29 June 2022
Condition: New
Quantity: 1 available
Add to basketPaperback. Linux Forensics is the most comprehensive and up-to-date resource for those wishing to quickly and efficiently perform forensics on Linux systems. It is also a great asset for anyone that would like to better understand Linux internals. Linux Forensics will guide you step by step through the process of investigating a computer running Linux. Everything you need to know from the moment you receive the call from someone who thinks they have been attacked until the final report is written is covered in this book. All of the tools discussed in this book are free and most are also open source. Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Linux systems. While readers will have a strong grasp of Python and shell scripting by the time they complete this book, no prior knowledge of either of these scripting languages is assumed. Linux Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images. Linux Forensics contains extensive coverage of Linux ext2, ext3, and ext4 filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussions of advanced attacks and malware analysis round out the book. Book Highlights 370 pages in large, easy-to-read 8.5 x 11 inch formatOver 9000 lines of Python scripts with explanationsOver 800 lines of shell scripts with explanationsA 102 page chapter containing up-to-date information on the ext4 filesystemTwo scenarios described in detail with images available from the book websiteAll scripts and other support files are available from the book website Chapter Contents First Steps General PrinciplesPhases of InvestigationHigh-level ProcessBuilding a ToolkitDetermining If There Was an IncidentOpening a CaseTalking to UsersDocumenationMounting Known-good BinariesMinimizing Disturbance to the SubjectAutomation With ScriptingLive AnalysisGetting MetadataUsing SpreadsheetsGetting Command HistoriesGetting LogsUsing HashesDumping RAMCreating ImagesShutting Down the SystemImage FormatsDDDCFLDDWrite BlockingImaging Virtual MachinesImaging Physical DrivesMounting ImagesMaster Boot Record Based PartionsGUID Partition TablesMounting Partitions In LinuxAutomating With PythonAnalyzing Mounted ImagesGetting TimestampsUsing LibreOfficeUsing MySQLCreating TimelinesExtended FilesystemsBasicsSuperblocksFeaturesUsing PythonFinding Things That Are Out Of PlaceInodesJournalingMemory AnalysisVolatilityCreating ProfilesLinux CommandsDealing With More Advanced AttackersMalwareIs It Malware?Malware Analysis ToolsStatic AnalysisDynamic AnalysisObfuscationThe Road AheadLearning MoreCommunitiesConferencesCertifications This it Shipping may be from our UK warehouse or from our Australian or US warehouses, depending on stock availability.
Seller Inventory # 9781515037637
Linux Forensics is the most comprehensive and up-to-date resource for those wishing to quickly and efficiently perform forensics on Linux systems. It is also a great asset for anyone that would like to better understand Linux internals.
Linux Forensics will guide you step by step through the process of investigating a computer running Linux. Everything you need to know from the moment you receive the call from someone who thinks they have been attacked until the final report is written is covered in this book. All of the tools discussed in this book are free and most are also open source.
Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Linux systems. While readers will have a strong grasp of Python and shell scripting by the time they complete this book, no prior knowledge of either of these scripting languages is assumed. Linux Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images.
Linux Forensics contains extensive coverage of Linux ext2, ext3, and ext4 filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussions of advanced attacks and malware analysis round out the book.
Book Highlights
Chapter Contents
Dr. Philip Polstra (known to his friends as Dr. Phil) is an internationally recognized hardware hacker. His work has been presented at numerous conferences around the globe including repeat performances at DEFCON (six presentations in four years), BlackHat, 44CON, GrrCON, MakerFaire, ForenSecure, and other top conferences. Dr. Polstra is a well-known expert on USB forensics and has published several articles on this topic. He has developed a number of video courses including ones on Linux forensics, USB forensics, and reverse engineering.
Dr. Polstra has developed degree programs in digital forensics and ethical hacking while serving as a professor and Hacker in Residence at a private university in the Midwestern United States. He currently teaches in one of the top Digital Forensics degree programs in the United States at Bloomsburg University of Pennsylvania. In addition to teaching, he provides training and performs penetration tests on a consulting basis. When not working, he has been known to fly, build aircraft, and tinker with electronics. He is an accomplished aviator with thousands of hours of flight time and a dozen ratings as a pilot, flight instructor, mechanic, aircraft inspector, and avionics specialist. His latest happenings can be found on his website http://philpolstra.com. You can also follow him at @ppolstra on Twitter.
Dr. Polstra authored Hacking and Penetration Testing with Low Power Devices (Syngress, 2014) in which he showed the world how to easily build drop boxes, hacking consoles, and remote hacking drones with the BeagleBone Black and similar devices. In the course of creating these devices he developed his own Linux, Deck Linux, which is optimized for security testing with ARM-based devices. Techniques described in this book permit security penetration tests to be performed with multiple, possibly battery powered, devices which are controlled by a user up to two miles away from the target organization.
His latest book, Linux Forensics (Pentester Academy, 2015), is the most comprehensive and up-to-date resource available to anyone wishing to perform forensics on Linux systems. The first printing of this book sold out in under twenty five hours. This book is considered a must have by a number of forensic investigators around the world.
"About this title" may belong to another edition of this title.
Orders can be returned within 30 days of receipt.
If you are a consumer you can cancel the contract in accordance with the following. Consumer means any natural person who is acting for purposes which are outside his trade, business, craft or profession.
INFORMATION REGARDING THE RIGHT OF CANCELLATION
Statutory Right to cancel
You have the right to cancel this contract within 14 days without giving any reason.
The cancellation period will expire after 14 days from the day on which you acquire, or a third party other than the carrier and indicated by you acquires, physical possession of the the last good or the last lot or piece.
To exercise the right to cancel, you must inform us, CitiRetail, ABC Books c/o International Logistics, Unit 2D Gatwick Gate Industrial Estate, RH11 0TG, Lowfield Heath, United Kingdom, 44 020 3290 3457, of your decision to cancel this contract by a clear statement (e.g. a letter sent by post, fax or e-mail). You may use the attached model cancellation form, but it is not obligatory. You can also electronically fill in and submit a clear statement on our website, under "My Purchases" in "My Account". If you use this option, we will communicate to you an acknowledgement of receipt of such a cancellation on a durable medium (e.g. by e-mail) without delay.
To meet the cancellation deadline, it is sufficient for you to send your communication concerning your exercise of the right to cancel before the cancellation period has expired.
Effects of cancellation
If you cancel this contract, we will reimburse to you all payments received from you, including the costs of delivery (except for the supplementary costs arising if you chose a type of delivery other than the least expensive type of standard delivery offered by us).
We may make a deduction from the reimbursement for loss in value of any goods supplied, if the loss is the result of unnecessary handling by you.
We will make the reimbursement without undue delay, and not later than 14 days after the day on which we are informed about your decision to cancel with contract.
We will make the reimbursement using the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in any event, you will not incur any fees as a result of such reimbursement.
We may withhold reimbursement until we have received the goods back or you have supplied evidence of having sent back the goods, whichever is the earliest.
You shall send back the goods or hand them over to us or CitiRetail, ABC Books c/o International Logistics, Unit 2D Gatwick Gate Industrial Estate, RH11 0TG, Lowfield Heath, United Kingdom, 44 020 3290 3457, without undue delay and in any event not later than 14 days from the day on which you communicate your cancellation from this contract to us. The deadline is met if you send back the goods before the period of 14 days has expired. You will have to bear the direct cost of returning the goods. You are only liable for any diminished value of the goods resulting from the handling other than what is necessary to establish the nature, characteristics and functioning of the goods.
Exceptions to the right of cancellation
The right of cancellation does not apply to:
Model withdrawal form
(complete and return this form only if you wish to withdraw from the contract)
To: (CitiRetail, ABC Books c/o International Logistics, Unit 2D Gatwick Gate Industrial Estate, RH11 0TG, Lowfield Heath, United Kingdom, 44 020 3290 3457)
I/We (*) hereby give notice that I/We (*) withdraw from my/our (*) contract of sale of the following goods (*)/for the provision of the following goods (*)/for the provision of the following service (*),
Ordered on (*)/received on (*)
Name of consumer(s)
Address of consumer(s)
Signature of consumer(s) (only if this form is notified on paper)
Date
* Delete as appropriate.
Please note that titles are dispatched from our US, Canadian or Australian warehouses. Delivery times specified in shipping terms. Orders ship within 2 business days. Delivery to your door then takes 7-14 days.
| Order quantity | 7 to 60 business days | 7 to 14 business days |
|---|---|---|
| First item | £ 37.00 | £ 37.00 |
Delivery times are set by sellers and vary by carrier and location. Orders passing through Customs may face delays and buyers are responsible for any associated duties or fees. Sellers may contact you regarding additional charges to cover any increased costs to ship your items.