官术网_书友最值得收藏!

  • Practical Windows Forensics
  • Ayman Shaaban Konstantin Sapronov
  • 235字
  • 2021-07-14 11:28:05

Analysis approaches

During incident handling, each case can be considered as a different scenario. Therefore, different approaches can take place during the first response, based on the circumstances of the individual case. There are two general approaches that can be used to deal with a security incident:

  • Live analysis: This is usually performed when the analyst has a live system in hand. Shutting the system down is one of the "don'ts" that the responder shouldn't do. Performing some primary analysis of the live system can provide valuable information that can guide the analyst in the future investigation. Also, in some situations, a quick analysis of the incident is highly required when there is no time to go through the normal steps of the analysis.
  • Postmortem analysis: This is the normal steps of the process, where the responder acquires all the available data from the incident scene, and then conducts postmortem analysis on the evidence.

Mainly, the hybrid approach is considered the best, where the responder conducts the live analysis on the powered on and accessible systems, records their findings, and acquires all the data, including the live ones, for postmortem analysis. Combining both results from live and postmortem analysis can clearly explain the status of the system under investigation. Performing the acquisition first in such a case is the best practice as the evidence will be acquired before any analysis traces are in the system.

主站蜘蛛池模板: 襄樊市| 英超| 藁城市| 新河县| 广宁县| 侯马市| 汕尾市| 大庆市| 贺州市| 若羌县| 肇源县| 漳州市| 固始县| 佛坪县| 武乡县| 扶余县| 武宁县| 蒲城县| 瑞安市| 涟源市| 舞钢市| 南充市| 平果县| 阳新县| 灯塔市| 奎屯市| 广东省| 广昌县| 富民县| 弥勒县| 哈密市| 茌平县| 烟台市| 陇南市| 揭阳市| 安泽县| 锦屏县| 泰顺县| 璧山县| 合阳县| 东城区|