Computer forensics–the art and science of gathering and analyzing digital evidence, reconstructing data and attacks, and tracking perpetrators–is becoming ever more important as IT and law enforcement professionals face an epidemic in computer crime. In Forensic Discovery, two internationally recognized experts present a thorough and realistic guide to the subject.

Dan Farmer and Wietse Venema cover both theory and hands-on practice, introducing a powerful approach that can often recover evidence considered lost forever.

The authors draw on their extensive firsthand experience to cover everything from file systems, to memory and kernel hacks, to malware. They expose a wide variety of computer forensics myths that often stand in the way of success. Readers will find extensive examples from Solaris, FreeBSD, Linux, and Microsoft Windows, as well as practical guidance for writing one’s own forensic tools. The authors are singularly well-qualified to write this book: They personally created some of the most popular security tools ever written, from the legendary SATAN network scanner to the powerful Coroner’s Toolkit for analyzing UNIX break-ins.

After reading this book you will be able to
Understand essential forensics concepts: volatility, layering, and trust
Gather the maximum amount of reliable evidence from a running system
Recover partially destroyed information–and make sense of it
Timeline your system: understand what really happened when
Uncover secret changes to everything from system utilities to kernel modules
Avoid cover-ups and evidence traps set by intruders
Identify the digital footprints associated with suspicious activity
Understand file systems from a forensic analyst’s point of view
Analyze malware–without giving it a chance to escape
Capture and examine the contents of main memory on running systems
Walk through the unraveling of an intrusion, one step at a time

The book’s companion Web site contains complete source and binary code for open source software discussed in the book, plus additional computer forensics case studies and resource links.

http://rapidshare.de/files/36789679/forensic-discovery-book.zip.htm