- Digital Forensics and Incident Response
- Gerard Johansen
- 143字
- 2021-07-02 18:49:47
Examination
The examination phase details the specific tools and forensic techniques that are utilized to discover and extract data from the evidence that is seized as part of the incident. For example, in a case where malware is suspected of infecting a desktop system as part of a larger attack, the extraction of specific information from an acquired memory image would take part in this stage. In other cases, digital forensic examiners may need to extract Secure Shell (SSH) traffic from a network capture. The examination of digital evidence also continues the process of proper preservation in that examiners maintain the utmost care with the evidence during the examination. If the digital forensic examiner does not take care in the preservation of the evidence in this stage, there is the possibility of contamination that would result in the evidence being unreliable or unusable.
- ClickHouse性能之巔:從架構設計解讀性能之謎
- Learning SAP Analytics Cloud
- Hands-On Natural Language Processing with Python
- C語言程序設計實驗指導 (第2版)
- NGINX Cookbook
- C語言程序設計
- 深入理解C指針
- Developing SSRS Reports for Dynamics AX
- CRYENGINE Game Development Blueprints
- 數據科學中的實用統計學(第2版)
- LabVIEW數據采集
- 軟件測試(慕課版)
- SAS編程演義
- JBoss AS 7 Development
- 前端Serverless:面向全棧的無服務器架構實戰