Cyber forensics: From Data to Digital Evidence
As a cyber forensic investigator, simply pressing buttons or ticking off options on forensic software¿without understanding what is happening behind the scenes¿creates a gaping hole in your company's infosecurity. Painting a broad picture of the field, Cyber Forensics provides you with the specific knowledge you need to not only find key data in forensic investigations but also speak confidently about the validity of the data identified, accessed, and analyzed as part of a comprehensive cyber forensic investigation.
Authors Albert Marcella and Frederic Guillossou¿both forensic and IT specialists¿begin by explaining the origins of data. From there, the authors address concepts related to data storage, boot records, partitions, volumes, and file systems, and how each of these is interrelated and essential in a cyber forensic investigation. They then analyze the roles these concepts play in an investigation and what type of evidential data may be identified within each of these areas.
Providing a thorough foundation to this emerging field, this step-by-step reference covers: