Having completed the acquisition of digital evidence in section two, section three focuses on proper analysis techniques in digital forensics. This section will focus on the appropriate tools and techniques to determine the root cause of an incident.
This section comprises the following chapters:
- Chapter 7, Analyzing Network Evidence
- Chapter 8, Analyzing System Memory
- Chapter 9, Analyzing System Storage
- Chapter 10, Analyzing Log Files
- Chapter 11, Writing the Incident Report