Part 3: Evidence Analysis
Having completed the acquisition of digital evidence in Part 2, Part 3 will focus on the proper analysis techniques of digital forensics. This part will focus on the proper tools and techniques to determine the root cause of an incident.
This part comprises the following chapters:
- Chapter 9, Analyzing Network Evidence
- Chapter 10, Analyzing System Memory
- Chapter 11, Analyzing System Storage
- Chapter 12, Analyzing Log Files
- Chapter 13, Writing the Incident Report