• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Ljudböcker
  • Pocketböcker
  • Spel och pussel

Skapa nya rutiner – hälsoböcker upp till 50% →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Investigating the Cyber Breach

    The Digital Forensics Guide for the Network Engineer

    AvJoseph Muniz,Aamir Lakhani

    Häftad, Engelska, 2018

    345 kr

    Beställningsvara. Skickas inom 7-10 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Investigating the Cyber Breach

    The Digital Forensics Guide for the Network Engineer

    · Understand the realities of cybercrime and today’s attacks

    · Build a digital forensics lab to test tools and methods, and gain expertise

    · Take the right actions as soon as you discover a breach

    · Determine the full scope of an investigation and the role you’ll play

    · Properly collect, document, and preserve evidence and data

    · Collect and analyze data from PCs, Macs, IoT devices, and other endpoints

    · Use packet logs, NetFlow, and scanning to build timelines, understand network activity, and collect evidence

    · Analyze iOS and Android devices, and understand encryption-related obstacles to investigation

    · Investigate and trace email, and identify fraud or abuse

    · Use social media to investigate individuals or online identities

    · Gather, extract, and analyze breach data with Cisco tools and techniques

    · Walk through common breaches and responses from start to finish

    · Choose the right tool for each task, and explore alternatives that might also be helpful

    The professional’s go-to digital forensics resource for countering attacks right now

    Today, cybersecurity and networking professionals know they can’t possibly prevent every breach, but they can substantially reduce risk by quickly identifying and blocking breaches as they occur. Investigating the Cyber Breach: The Digital Forensics Guide for the Network Engineer is the first comprehensive guide to doing just that.

    Writing for working professionals, senior cybersecurity experts Joseph Muniz and Aamir Lakhani present up-to-the-minute techniques for hunting attackers, following their movements within networks, halting exfiltration of data and intellectual property, and collecting evidence for investigation and prosecution. You’ll learn how to make the most of today’s best open source and Cisco tools for cloning, data analytics, network and endpoint breach detection, case management, monitoring, analysis, and more.

    Unlike digital forensics books focused primarily on post-attack evidence gathering, this one offers complete coverage of tracking threats, improving intelligence, rooting out dormant malware, and responding effectively to breaches underway right now.

    This book is part of the Networking Technology: Security Series from Cisco Press®, which offers networking professionals valuable information for constructing efficient networks, understanding new technologies, and building successful careers.

    Produktinformation

    • Utgivningsdatum:2018-10-02
    • Mått:186 x 230 x 24 mm
    • Vikt:785 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:464
    • Upplaga:1
    • Förlag:Pearson Education
    • ISBN:9781587145025

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • It-certifieringar inom Data och IT
    • Cisco-certifiering inom Data och IT

    Mer om författaren

    Joseph Muniz is an architect at Cisco Systems and a security researcher. He has extensive experience in designing security solutions and architectures for the top Fortune 500 corporations and the U.S. government. Joseph’s current role gives him visibility into the latest trends in cybersecurity, from both leading vendors and customers. Examples of Joseph’s research include his RSA talk titled “Social Media Deception,” which has been quoted by many sources (search for “Emily Williams Social Engineering”), as well as his articles in PenTest Magazine regarding various security topics. Joseph runs The Security Blogger website, a popular resource for security, hacking, and product implementation. He is the author and contributor of several publications covering various penetration testing, certification, and security topics. You can follow Joseph at www.thesecurityblogger.com and @SecureBlogger.Aamir Lakhani is a leading senior security strategist. He is responsible for providing IT security solutions to major enterprises and government organizations. Aamir creates technical security strategies and leads security implementation projects for Fortune 500 companies. Industries of focus include healthcare providers, educational institutions, financial institutions, and government organizations. He has designed offensive counter-defense measures for the Department of Defense and national intelligence agencies. He has also assisted organizations with safeguarding IT and physical environments from attacks perpetrated by underground cybercriminal groups. Aamir is considered an industry leader for creating detailed security architectures within complex computing environments. His areas of expertise include cyber defense, mobile application threats, malware management, Advanced Persistent Threat (APT) research, and investigations relating to the Internet’s dark security movement.

    Innehållsförteckning

    • Introduction xixChapter 1 Digital Forensics 1Defining Digital Forensics 3Engaging Forensics Services 4Reporting Crime 7Search Warrant and Law 9Forensic Roles 13Forensic Job Market 15Forensic Training 16Summary 23References 24Chapter 2 Cybercrime and Defenses 25Crime in a Digital Age 27Exploitation 31Adversaries 34Cyber Law 36Summary 39Reference 39Chapter 3 Building a Digital Forensics Lab 41Desktop Virtualization 42VMware Fusion 43VirtualBox 44Installing Kali Linux 44Attack Virtual Machines 52Cuckoo Sandbox 56Virtualization Software for Cuckoo 58Installing TCPdump 58Creating a User on VirtualBox for Cuckoo 59Binwalk 60The Sleuth Kit 61Cisco Snort 62Windows Tools 67Physical Access Controls 68Storing Your Forensics Evidence 71Network Access Controls 72Jump Bag 74Summary 74References 75Chapter 4 Responding to a Breach 77Why Organizations Fail at Incident Response 78Preparing for a Cyber Incident 80Defining Incident Response 81Incident Response Plan 82Assembling Your Incident Response Team 84When to Engage the Incident Response Team 85Outstanding Items that Often Get Missed with Incident Response 88Phone Tree and Contact List 88Facilities 89Responding to an Incident 89Assessing Incident Severity 91Following Notification Procedures 92Employing Post-Incident Actions and Procedures 93Identifying Software Used to Assist in Responding to a Breach 93Trend Analysis Software 94Security Analytics Reference Architectures 94Other Software Categories 97Summary 97References 98Chapter 5 Investigations 99Pre-Investigation 100Opening a Case 102First Responder 105Device Power State 110Search and Seizure 113Chain of Custody 118Network Investigations 121Forensic Reports 127Case Summary 129Example 129Acquisition and Exam Preparation 129Example 129Findings 130Example 130Conclusion 130Example 131List of Authors 131Example 131Closing the Case 132Critiquing the Case 136Summary 139References 139Chapter 6 Collecting and Preserving Evidence 141First Responder 141Evidence 144Autopsy 145Authorization 147Hard Drives 148Connections and Devices 150RAID 152Volatile Data 153DumpIt 154LiME 154Volatility 156Duplication 158dd 161dcfldd 161ddrescue 162Netcat 162Guymager 163Compression and Splitting 164Hashing 166MD5 and SHA Hashing 168Hashing Challenges 169Data Preservation 170Summary 172References 172Chapter 7 Endpoint Forensics 173File Systems 174Locating Data 178Unknown Files 180Windows Registry 182Deleted Files 185Windows Recycle Bin 187Shortcuts 189Printer Spools 190Slack Space and Corrupt Clusters 191Alternate Data Streams 196Mac OS X 198OS X Artifacts 199Log Analysis 202IoT Forensics 207Summary 210References 211Chapter 8 Network Forensics 213Network Protocols 214Security Tools 215Firewall 219Intrusion Detection and Prevention System 219Content Filter 219Network Access Control 220Packet Capturing 223NetFlow 224Sandbox 225Honeypot 226Security Information and Event Manager (SIEM) 228Threat Analytics and Feeds 229Security Tool Summary 229Security Logs 229Network Baselines 233Symptoms of Threats 235Reconnaissance 235Exploitation 238Malicious Behavior 242Beaconing 244Brute Force 249Exfiltration 250Other Indicators 254Summary 255References 255Chapter 9 Mobile Forensics 257Mobile Devices 258Investigation Challenges 258iOS Architecture 259iTunes Forensics 261iOS Snapshots 263How to Jailbreak the iPhone 265Android 266PIN Bypass 270How to Brute Force Passcodes on the Lock Screen 271Forensics with Commercial Tools 272Call Logs and SMS Spoofing 274Voicemail Bypass 275How to Find Burner Phones 276SIM Card Cloning 278Summary 279Reference 279Chapter 10 Email and Social Media 281A Message in a Bottle 281Email Header 283Social Media 288People Search 288Google Search 293Facebook Search 297Summary 304References 305Chapter 11 Cisco Forensic Capabilities 307Cisco Security Architecture 307Cisco Open Source 310Cisco Firepower 312Cisco Advanced Malware Protection (AMP) 313Cisco Threat Grid 319Cisco Web Security Appliance 322Cisco CTA 323Meraki 324Email Security Appliance 326Cisco Identity Services Engine 328Cisco Stealthwatch 331Cisco Tetration 335Cisco Umbrella 337Cisco Cloudlock 342Cisco Network Technology 343Summary 343Reference 343Chapter 12 Forensic Case Studies 345Scenario 1: Investigating Network Communication 346Pre-engagement 347Investigation Strategy for Network Data 348Investigation 350Closing the Investigation 355Scenario 2: Using Endpoint Forensics 357Pre-engagement 357Investigation Strategy for Endpoints 358Investigation 359Potential Steps to Take 360Closing the Investigation 362Scenario 3: Investigating Malware 364Pre-engagement 364Investigation Strategy for Rogue Files 365Investigation 365Closing the Investigation 369Scenario 4: Investigating Volatile Data 370Pre-engagement 371Investigation Strategy for Volatile Data 372Investigation 373Closing the Investigation 375Scenario 5: Acting as First Responder 377Pre-engagement 377First Responder Strategy 377Closing the Investigation 379Summary 381References 382Chapter 13 Forensic Tools 383Tools 384Slowloris DDOS Tool: Chapter 2 385Low Orbit Ion Cannon 386VMware Fusion: Chapter 3 386VirtualBox: Chapter 3 387Metasploit: Chapter 3 388Cuckoo Sandbox: Chapter 3 389Cisco Snort: Chapter 3 389FTK Imager: Chapters 3, 9 390FireEye Redline: Chapter 3 391P2 eXplorer: Chapter 3 392PlainSight: Chapter 3 392Sysmon: Chapter 3 393WebUtil: Chapter 3 393ProDiscover Basics: Chapter 3 393Solarwinds Trend Analysis Module: Chapter 4 394Splunk: Chapter 4 394RSA Security Analytics: Chapter 4 395IBM’s QRadar: Chapter 4 396HawkeyeAP: Chapter 4 396WinHex: Chapters 6, 7 396OSForensics: Chapter 6 397Mount Image Pro: Chapter 6 397DumpIt: Chapter 6 398LiME: Chapter 6 398TrIDENT: Chapter 7 398PEiD: Chapter 7 399Lnkanalyser: Chapter 7 399Windows File Analyzer: Chapter 7 399LECmd: Chapter 7 401SplViewer: Chapter 7 401PhotoRec: Chapter 7 402Windows Event Log: Chapter 7 402Log Parser Studio: Chapter 7 403LogRhythm: Chapter 8 403Mobile Devices 404Elcomsoft: Chapter 9 404Cellebrite: Chapter 9 404iPhone Backup Extractor: Chapter 9 405iPhone Backup Browser: Chapter 9 405Pangu: Chapter 9 405KingoRoot Application: Chapter 9 405Kali Linux Tools 406Fierce: Chapter 8 406TCPdump: Chapter 3 406Autopsy and Autopsy with the Sleuth Kit: Chapters 3, 6 406Wireshark: Chapter 8 406Exiftool: Chapter 7 407DD: Chapter 6 407Dcfldd: Chapter 6 408Ddrescue: Chapter 6 408Netcat: Chapter 6 408Volatility: Chapter 6 408Cisco Tools 408Cisco AMP 408Stealthwatch: Chapter 8 409Cisco WebEx: Chapter 4 409Snort: Chapter 11 409ClamAV: Chapter 10 409Razorback: Chapter 10 410Daemonlogger: Chapter 10 410Moflow Framework: Chapter 10 410Firepower: Chapter 10 410Threat Grid: Chapter 10 410WSA: Chapter 10 410Meraki: Chapter 10 411Email Security: Chapter 10 411ISE: Chapter 10 411Cisco Tetration: Chapter 10 411Umbrella: Chapter 10 411Norton ConnectSafe: No Chapter 412Cloudlock: Chapter 10 412Forensic Software Packages 413FTK Toolkit: Chapter 3 413X-Ways Forensics: Chapter 3 413OSforensics: Chapter 6 414EnCase: Chapter 7 414Digital Forensics Framework (DFF): Chapter 7 414Useful Websites 414Shodan: Chapter 1 414Wayback Machine: Chapter 3 415Robot.txt files: Chapter 2 415Hidden Wiki: Chapter 2 415NIST: Chapter 4 416CVE: Chapter 4 416Exploit-DB: Chapter 4 416Pastebin: Chapters 4, 10 416University of Pennsylvania Chain of Custody Form: Chapter 6 417List of File Signatures: Chapter 9 417Windows Registry Forensics Wiki: Chapter 7 417Mac OS Forensics Wiki: Chapter 7 417Miscellaneous Sites 417Searchable FCC ID Database 418Service Name and Transport Protocol Port Number Registry 418NetFlow Version 9 Flow-Record Format 418NMAP 418Pwnable 418Embedded Security CTF 419CTF Learn 419Reversing.Kr 419Hax Tor 419W3Challs 419RingZer0 Team Online CTF 420Hellbound Hackers 420Over the Wire 420Hack This Site 420VulnHub 420Application Security Challenge 421iOS Technology Overview 421Summary 4219781587145025 TOC 1/10/2017
    Hoppa över listan

    Mer från samma författare

    Joseph Muniz, Gary McIntyre, Nadhem AlFardan - Security Operations Center, Häftad

    Security Operations Center

    Joseph Muniz, Gary McIntyre, Nadhem AlFardan

    Häftad, 2015

    377 kr

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz - Security Operations Center, E-bok

    Security Operations Center

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz

    E-bok
    2015

    594 kr

    Joseph Muniz - Modern Security Operations Center, The, Häftad

    Modern Security Operations Center, The

    Joseph Muniz

    Häftad, 2021

    419 kr

    Joseph Muniz, Steven Chimes, James Risler - CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide, Övrigt

    CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide

    Joseph Muniz, Steven Chimes, James Risler

    569 kr

    Omar Santos, Joseph Muniz, Stefano De Crescenzo - CCNA Cyber Ops SECFND #210-250 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECFND #210-250 Official Cert Guide

    Omar Santos, Joseph Muniz, Stefano De Crescenzo

    867 kr

    Omar Santos, Joseph Muniz - CCNA Cyber Ops SECOPS 210-255 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECOPS 210-255 Official Cert Guide

    Omar Santos, Joseph Muniz

    875 kr

    Joseph Muniz, Aamir Lakhani - Web Penetration Testing with Kali Linux, Häftad

    Web Penetration Testing with Kali Linux

    Joseph Muniz, Aamir Lakhani

    Häftad, 2013

    730 kr

    Aamir Lakhani, Joseph Muniz - Penetration Testing with Raspberry Pi, Häftad

    Penetration Testing with Raspberry Pi

    Aamir Lakhani, Joseph Muniz

    Häftad, 2015

    454 kr

    Hoppa över listan

    Du kanske också är intresserad av

    Aamir Lakhani, Joseph Muniz - Penetration Testing with Raspberry Pi, Häftad

    Penetration Testing with Raspberry Pi

    Aamir Lakhani, Joseph Muniz

    Häftad, 2015

    454 kr

    Joseph Muniz, Aamir Lakhani - Web Penetration Testing with Kali Linux, Häftad

    Web Penetration Testing with Kali Linux

    Joseph Muniz, Aamir Lakhani

    Häftad, 2013

    730 kr

    Aamir Lakhani - Instant XenMobile MDM, Häftad

    Instant XenMobile MDM

    Aamir Lakhani

    Häftad, 2013

    405 kr

    Aamir Lakhani, Anthony Giandomenico - Cisco Security Fundamentals, Häftad

    Cisco Security Fundamentals

    Aamir Lakhani, Anthony Giandomenico

    Häftad, 2024

    434 kr

    Omar Santos, Joseph Muniz, Stefano De Crescenzo - CCNA Cyber Ops SECFND #210-250 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECFND #210-250 Official Cert Guide

    Omar Santos, Joseph Muniz, Stefano De Crescenzo

    867 kr

    Joseph Muniz, Steven Chimes, James Risler - CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide, Övrigt

    CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide

    Joseph Muniz, Steven Chimes, James Risler

    569 kr

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz - Security Operations Center, E-bok

    Security Operations Center

    Nadhem AlFardan, Gary McIntyre, Joseph Muniz

    E-bok
    2015

    594 kr

    Joseph Muniz, Gary McIntyre, Nadhem AlFardan - Security Operations Center, Häftad

    Security Operations Center

    Joseph Muniz, Gary McIntyre, Nadhem AlFardan

    Häftad, 2015

    377 kr

    Omar Santos, Joseph Muniz - CCNA Cyber Ops SECOPS 210-255 Official Cert Guide, Övrigt

    CCNA Cyber Ops SECOPS 210-255 Official Cert Guide

    Omar Santos, Joseph Muniz

    875 kr

    Joseph Muniz - Modern Security Operations Center, The, Häftad

    Modern Security Operations Center, The

    Joseph Muniz

    Häftad, 2021

    419 kr