• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Ljudböcker
  • Pocketböcker
  • Spel och pussel

Skapa nya rutiner – hälsoböcker upp till 50% →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. IT-säkerhet

    Art of Memory Forensics

    Detecting Malware and Threats in Windows, Linux, and Mac Memory

    AvMichael Hale Ligh,Andrew Case

    Häftad, Engelska, 2014

    748 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Memory forensics provides cutting edge technology to help investigate digital attacks Memory forensics is the art of analyzing computer memory (RAM) to solve digital crimes. As a follow-up to the best seller Malware Analyst's Cookbook, experts in the fields of malware, security, and digital forensics bring you a step-by-step guide to memory forensics—now the most sought after skill in the digital forensics and incident response fields.Beginning with introductory concepts and moving toward the advanced, The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory is based on a five day training course that the authors have presented to hundreds of students. It is the only book on the market that focuses exclusively on memory forensics and how to deploy such techniques properly. Discover memory forensics techniques: How volatile memory analysis improves digital investigationsProper investigative steps for detecting stealth malware and advanced threatsHow to use free, open source tools for conducting thorough memory forensicsWays to acquire memory from suspect systems in a forensically sound mannerThe next era of malware and security breaches are more sophisticated and targeted, and the volatile memory of a computer is often overlooked or destroyed as part of the incident response process. The Art of Memory Forensics explains the latest technological innovations in digital forensics to help bridge this gap. It covers the most popular and recently released versions of Windows, Linux, and Mac, including both the 32 and 64-bit editions.

    Produktinformation

    • Utgivningsdatum:2014-10-03
    • Mått:185 x 234 x 46 mm
    • Vikt:1 498 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:912
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781118825099

    Utforska kategorier

    • IT-säkerhet inom Data och IT

    Mer om författaren

    Michael Hale-Ligh is author of Malware Analyst's Cookbook, Secretary/Treasurer of Volatility Foundation, and a world-class reverse engineer. Andrew Case is a Digital Forensics Researcher specializing in memory, disk, and network forensics.Jamie Levy is a Senior Researcher and Developer, targeting memory, network, and malware forensics analysis.AAron Walters is founder and lead developer of the Volatility Project, President of the Volatility Foundation, and Chair of Open Memory Forensics Workshop.

    Innehållsförteckning

    • Introduction xvii I An Introduction to Memory Forensics 11 Systems Overview 3Digital Environment 3PC Architecture 4Operating Systems  17Process Management 18Memory Management   20File System 24I/O Subsystem 25Summary 262 Data Structures  27Basic Data Types   27Summary 433 The Volatility Framework  45Why Volatility? 45What Volatility Is Not   46Installation 47The Framework 51Using Volatility 59Summary 674 Memory Acquisition 69Preserving the Digital Environment 69Software Tools 79Memory Dump Formats 95Converting Memory Dumps 106Volatile Memory on Disk 107Summary 114II Windows Memory Forensics 1155 Windows Objects and Pool Allocations 117Windows Executive Objects  117Pool-Tag Scanning 129Limitations of Pool Scanning 140Big Page Pool 142Pool-Scanning Alternatives  146Summary 1486 Processes, Handles, and Tokens 149Processes  149Process Tokens 164Privileges 170Process Handles 176Enumerating Handles in Memory 181Summary 1877 Process Memory Internals  189What’s in Process Memory? 189Enumerating Process Memory 193Summary 2178 Hunting Malware in Process Memory 219Process Environment Block  219PE Files in Memory 238Packing and Compression   245Code Injection 251Summary 2639 Event Logs 265Event Logs in Memory  265Real Case Examples 275Summary 27910 Registry in Memory  281Windows Registry Analysis  281Volatility’s Registry API 292Parsing Userassist Keys 295Detecting Malware with the Shimcache 297Reconstructing Activities with Shellbags   298Dumping Password Hashes  304Obtaining LSA Secrets  305Summary 30711 Networking 309Network Artifacts  309Hidden Connections 323Raw Sockets and Sniffers 325Next Generation TCP/IP Stack   327Internet History   333DNS Cache Recovery   339Summary 34112 Windows Services 343Service Architecture 343Installing Services 345Tricks and Stealth 346Investigating Service Activity 347Summary 36613 Kernel Forensics and Rootkits 367Kernel Modules   367Modules in Memory Dumps 372Threads in Kernel Mode  378Driver Objects and IRPs 381Device Trees  386Auditing the SSDT 390Kernel Callbacks   396Kernel Timers 399Putting It All Together  402Summary 40614 Windows GUI Subsystem, Part I 407The GUI Landscape 407GUI Memory Forensics 410The Session Space  410Window Stations   416Desktops 422Atoms and Atom Tables 429Windows 435Summary 45215 Windows GUI Subsystem, Part II 453Window Message Hooks 453User Handles 459Event Hooks  466Windows Clipboard 468Case Study: ACCDFISA Ransomware 472Summary 47616 Disk Artifacts in Memory  477Master File Table  477Extracting Files   493Defeating TrueCrypt Disk Encryption  503Summary 51017 Event Reconstruction 511Strings  511Command History 523Summary 53618 Timelining 537Finding Time in Memory 537Generating Timelines   539Gh0st in the Enterprise 543Summary 573III Linux Memory Forensics 57519 Linux Memory Acquisition 577Historical Methods of Acquisition 577Modern Acquisition 579Volatility Linux Profiles 583Summary 58920 Linux Operating System 591ELF Files 591Linux Data Structures  603Linux Address Translation   607procfs and sysfs   609Compressed Swap   610Summary 61021 Processes and Process Memory 611Processes in Memory   611Enumerating Processes 613Process Address Space   616Process Environment Variables   625Open File Handles 626Saved Context State 630Bash Memory Analysis 630Summary 63522 Networking Artifacts 637Network Socket File Descriptors  637Network Connections   640Queued Network Packets 643Network Interfaces 646The Route Cache   650ARP Cache   652Summary65523 Kernel Memory Artifacts 657Physical Memory Maps 657Virtual Memory Maps  661Kernel Debug Buffer   663Loaded Kernel Modules 667Summary 67324 File Systems in Memory  675Mounted File Systems  675Listing Files and Directories 681Extracting File Metadata 684Recovering File Contents 691Summary 69525 Userland Rootkits  697Shellcode Injection 698Process Hollowing 703Shared Library Injection 705LD_PRELOAD Rootkits 712GOT/PLT Overwrites  716Inline Hooking 718Summary 71926 Kernel Mode Rootkits 721Accessing Kernel Mode 721Hidden Kernel Modules 722Hidden Processes  728Elevating Privileges 730System Call Handler Hooks  734Keyboard Notifiers 735TTY Handlers 739Network Protocol Structures 742Netfilter Hooks 745File Operations 748Inline Code Hooks 752Summary75427 Case Study: Phalanx2 755Phalanx2 755Phalanx2 Memory Analysis  757Reverse Engineering Phalanx2   763Final Thoughts on Phalanx2 772Summary 772IV Mac Memory Forensics 77328 Mac Acquisition and Internals 775Mac Design  775Memory Acquisition   780Mac Volatility Profiles  784Mach-O Executable Format 787Summary 79129 Mac Memory Overview 793Mac versus Linux Analysis  793Process Analysis   794Address Space Mappings 799Networking Artifacts   804SLAB Allocator   808Recovering File Systems from Memory 811Loaded Kernel Extensions   815Other Mac Plugins 818Mac Live Forensics 819Summary 82130 Malicious Code and Rootkits 823Userland Rootkit Analysis   823Kernel Rootkit Analysis 828Common Mac Malware in Memory   838Summary 84431 Tracking User Activity  845Keychain Recovery 845Mac Application Analysis   849Summary 858Index 859
    Hoppa över listan

    Mer från samma författare

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

    Attack and Defend Computer Security Set

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

    E-bok
    2014

    854 kr

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh - Art of Memory Forensics, E-bok

    Art of Memory Forensics

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh

    E-bok
    2014

    862 kr

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh - Art of Memory Forensics, E-bok

    Art of Memory Forensics

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh

    E-bok
    2014

    845 kr

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

    Attack and Defend Computer Security Set

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

    E-bok
    2014

    854 kr

    Hoppa över listan

    Du kanske också är intresserad av

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh - Art of Memory Forensics, E-bok

    Art of Memory Forensics

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh

    E-bok
    2014

    845 kr

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh - Art of Memory Forensics, E-bok

    Art of Memory Forensics

    AAron Walters, Jamie Levy, Andrew Case, Michael Hale Ligh

    E-bok
    2014

    862 kr

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

    Attack and Defend Computer Security Set

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

    E-bok
    2014

    854 kr

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

    Attack and Defend Computer Security Set

    Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

    E-bok
    2014

    854 kr

    Andrew Case - Big Fear, Ljudbok

    Big Fear

    Andrew Case

    Ljudbok
    2016

    238 kr

    Andrew Case - Falling Knife, Ljudbok

    Falling Knife

    Andrew Case

    Ljudbok
    2017

    159 kr

    Andrew Case - Study Guide for Essentials of Anatomy & Physiology, Häftad

    Study Guide for Essentials of Anatomy & Physiology

    Andrew Case

    Häftad, 2011

    647 kr

    Aaron Walters - Dog Training Bible for Dog Owners, Häftad

    Dog Training Bible for Dog Owners

    Aaron Walters

    Häftad, 2014

    147 kr

    Carola Häggkvist - SIGNERAD - Jag är Carola, Inbunden
    • Signerad!

    SIGNERAD - Jag är Carola

    Carola Häggkvist

    Inbunden, 2026

    269 kr

    Marcus Frank - SIGNERAD - Mackans kost : Middagar och matlådor, Inbunden
    • Signerad!

    SIGNERAD - Mackans kost : Middagar och matlådor

    Marcus Frank

    Inbunden, 2026

    269 kr