Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Digital Forensics with Kali Linux

You're reading from   Digital Forensics with Kali Linux Enhance your investigation skills by performing network and memory forensics with Kali Linux 2022.x

Arrow left icon
Product type Paperback
Published in Apr 2023
Publisher Packt
ISBN-13 9781837635153
Length 414 pages
Edition 3rd Edition
Arrow right icon
Author (1):
Arrow left icon
Shiva V. N. Parasram Shiva V. N. Parasram
Author Profile Icon Shiva V. N. Parasram
Shiva V. N. Parasram
Arrow right icon
View More author details
Toc

Table of Contents (24) Chapters Close

Preface 1. Part 1: Blue and Purple Teaming Fundamentals
2. Chapter 1: Red, Blue, and Purple Teaming Fundamentals FREE CHAPTER 3. Chapter 2: Introduction to Digital Forensics 4. Chapter 3: Installing Kali Linux 5. Chapter 4: Additional Kali Installations and Post-Installation Tasks 6. Chapter 5: Installing Wine in Kali Linux 7. Part 2: Digital Forensics and Incident Response Fundamentals and Best Practices
8. Chapter 6: Understanding File Systems and Storage 9. Chapter 7: Incident Response, Data Acquisitions, and DFIR Frameworks 10. Part 3: Kali Linux Digital Forensics and Incident Response Tools
11. Chapter 8: Evidence Acquisition Tools 12. Chapter 9: File Recovery and Data Carving Tools 13. Chapter 10: Memory Forensics and Analysis with Volatility 3 14. Chapter 11: Artifact, Malware, and Ransomware Analysis 15. Part 4: Automated Digital Forensics and Incident Response Suites
16. Chapter 12: Autopsy Forensic Browser 17. Chapter 13: Performing a Full DFIR Analysis with the Autopsy 4 GUI 18. Part 5: Network Forensic Analysis Tools
19. Chapter 14: Network Discovery Tools 20. Chapter 15: Packet Capture Analysis with Xplico 21. Chapter 16: Network Forensic Analysis Tools 22. Index 23. Other Books You May Enjoy

What this book covers

Chapter 1, Red, Blue, and Purple Teaming Fundamentals, informs you about the different types of cyber security teams to which penetration testers and forensic investigators belong, and the skillsets required.

Chapter 2, Introduction to Digital Forensics, introduces you to the world of digital forensics and forensic methodology, and also introduces you to various forensic operating systems.

Chapter 3, Installing Kali Linux, covers the various methods that can be used to install Kali Linux as a virtual machine or as a standalone operating system, which can also be run from a flash drive or SD card.

Chapter 4, Additional Kali Installations and Post-Installation Tasks, builds upon the Kali installation and guides you through performing additional installations and post-installation tasks such as enabling a root user and updating Kali Linux.

Chapter 5, Installing Wine in Kali Linux, shows the versatility of Linux systems, where you will learn how to install and use forensic tools designed to be used in the Windows platform, in a Kali Linux system using Wine.

Chapter 6, Understanding File Systems and Storage Media, dives into the realm of operating systems and the various formats for file storage, including secret hiding places not seen by the end user, or even the operating system. We also inspect data about data, known as metadata, and look at its volatility.

Chapter 7, Incident Response, Data Acquisitions, and DFIR Frameworks, asks what happens when an incident is reported or detected. Who are the first responders and what are the procedures for maintaining the integrity of the evidence? In this chapter, we look at best practices, procedures, and frameworks for data acquisition and evidence collection.

Chapter 8, Evidence Acquisition Tools, builds on the theory behind data acquisitions and best practices and teaches you to use industry-recognized tools such as DC3DD, DD, Guymager, FTK Imager, and RAM Capturer to perform data and image acquisition while preserving evidence integrity.

Chapter 9, File Recovery and Data Carving Tools, introduces the investigative side of digital forensics by using various tools such as Magic Rescue, Scalpel, Bulk_Extractor, scrounge_ntfs, and recoverjpeg to carve and recover data and artifacts from forensically acquired images and media.

Chapter 10, Memory Forensics and Analysis with Volatility 3, takes us into the analysis of memory artifacts and demonstrates the importance of preserving volatile evidence such as the contents of the RAM and the paging file.

Chapter 11, Artifact, Malware, and Ransomware Analysis, carries us much deeper into artifact analysis using p0f, swap_digger, and mimipenguin, and, thereafter, demonstrates how to perform malware and ransomware analysis using pdf-parser, hybrid-analysis.com, and Volatility.

Chapter 12, Autopsy Forensic Browser, showcases automated file recovery and analysis within Kali Linux using a single tool.

Chapter 13, Performing a Full DFIR Analysis with the Autopsy 4 GUI, dives much deeper into automated file carving, data recovery, and analysis using one of the most powerful and free forensic tools, which takes forensic abilities and investigations to a professional level, catering for all aspects of full digital forensics investigations, from hashing to reporting.

Chapter 14, Network Discovery Tools, showcases network scanning and reconnaissance tools such as netdiscover, nmap, and Shodan, which, although not specifically designed for use as forensic tools, are useful in providing additional information when performing incident response.

Chapter 15, Packet Capture Analysis with Xplico, gives an insightful use of automated packet analysis using one tool for investigating network and internet traffic.

Chapter 16, Network Forensic Analysis Tools, ends the book by demonstrating how to capture and analyze packets using a variety of tools and websites including Wireshark, NetworkMiner, packettotal.com, and apackets.com.

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime