دانلود کتاب Practical Linux Forensics: A Guide for Digital Investigators
by Bruce Nikkel
|
عنوان فارسی: پزشکی قانونی لینوکس عملی: راهنمای محققین دیجیتال |
دانلود کتاب
جزییات کتاب
Early chapters provide an overview of digital forensics as well as an introduction to the Linux operating system and popular distributions. From there, the book describes the analysis of storage, filesystems, files and directories, installed software packages, and logs. Special focus is given to examining human user activity such as logins, desktop environments and artifacts, home directories, regional settings, and peripheral devices used.
You’ll learn how to:
• Analyze partition tables, volume management, Linux filesystems, and directory layout
• Reconstruct the Linux startup process, from system boot and kernel initialization, to systemd unit files leading up to a graphical login
• Perform historical analysis of power, temperature, and physical environment, and find evidence of sleep, hibernation, shutdowns, reboots, and crashes
• Analyze network configuration, including interfaces, addresses, network managers, DNS, wireless artifacts, VPNs, firewalls, and proxy settings
• Perform analysis of time and locale settings, internationalization (language and keyboard settings), and Linux geolocation services
• Reconstruct user login sessions, analyze desktop artifacts, and identify traces of attached peripheral devices, including disks, printers, and mobile devices