Computer Forensics and Digital Investigation with EnCase Forensic v7 (Paperback)

Suzanne Widup

  • 出版商: McGraw-Hill Education
  • 出版日期: 2014-05-28
  • 定價: $1,650
  • 售價: 6.0$990
  • 語言: 英文
  • 頁數: 448
  • 裝訂: Paperback
  • ISBN: 0071807918
  • ISBN-13: 9780071807913
  • 立即出貨 (庫存=1)

買這商品的人也買了...

商品描述

Conduct repeatable, defensible investigations with EnCase Forensic v7

Maximize the powerful tools and features of the industry-leading digital investigation software. Computer Forensics and Digital Investigation with EnCase Forensic v7 reveals, step by step, how to detect illicit activity, capture and verify evidence, recover deleted and encrypted artifacts, prepare court-ready documents, and ensure legal and regulatory compliance. The book illustrates each concept using downloadable evidence from the National Institute of Standards and Technology CFReDS. Customizable sample procedures are included throughout this practical guide.

  • Install EnCase Forensic v7 and customize the user interface
  • Prepare your investigation and set up a new case
  • Collect and verify evidence from suspect computers and networks
  • Use the EnCase Evidence Processor and Case Analyzer
  • Uncover clues using keyword searches and filter results through GREP
  • Work with bookmarks, timelines, hash sets, and libraries
  • Handle case closure, final disposition, and evidence destruction
  • Carry out field investigations using EnCase Portable
  • Learn to program in EnCase EnScript

商品描述(中文翻譯)

使用 EnCase Forensic v7 進行可重複且可靠的調查

最大限度地發揮行業領先的數位調查軟體的強大工具和功能。《使用 EnCase Forensic v7 進行電腦取證和數位調查》逐步揭示了如何檢測非法活動、捕獲和驗證證據、恢復已刪除和加密的物件、準備適用於法庭的文件,以及確保合法和法規遵循。本書使用國家標準與技術研究所 CFReDS 的可下載證據來說明每個概念。本實用指南中包含可自訂的範例程序。

- 安裝 EnCase Forensic v7 並自訂使用者介面
- 準備調查並建立新案件
- 從嫌疑電腦和網路收集和驗證證據
- 使用 EnCase 證據處理器和案件分析器
- 通過關鍵字搜索和 GREP 過濾結果來發現線索
- 使用書籤、時間軸、哈希集和資料庫
- 處理案件結案、最終處置和證據銷毀
- 使用 EnCase Portable 進行現場調查
- 學習在 EnCase EnScript 中進行編程