The Digital Forensics and Incident Response Process
So far, we have mostly looked at cloud-native tools for investigators to review logs and perform analysis. In the subsequent chapters, we will be looking at some of the third-party tools that complement cloud-native tools – tools that can aid in collecting and analyzing forensic artifacts, marrying cloud-native and third-party toolsets every investigator should be familiar with before embarking upon a cloud forensic case. Specifically, this chapter will revisit the basics of digital forensics and the incident response process. We will also identify some core concepts and introduce tools we have typically used in cloud forensic cases.
In this chapter, we will learn about the following:
- The basics of the incident response process
- Commonly used tools and techniques for host and memory forensics
- Options to conduct live forensics
- Network forensics
- A refresher on malware analysis
- Traditional forensics...