{"product_id":"practical-forensic-imaging-securing-digital-evidence-with-linux-tools-9781593277932","title":"Practical Forensic Imaging: Securing Digital Evidence with Linux Tools","description":"\u003cp\u003e • Author(s): Bruce Nikkel\u003cbr\u003e • Publisher: No Starch Press\u003cbr\u003e • Publisher Imprint: No Starch Press\u003cbr\u003e • BISAC: System Administration - Storage \u0026amp; Retrieval\u003c\/p\u003e\u003cp\u003eForensic image acquisition is an important part of postmortem incident response and evidence collection. Digital forensic investigators acquire, preserve, and manage digital evidence to support civil and criminal cases; examine organizational policy violations; resolve disputes; and analyze cyber attacks. \u003c\/p\u003e\u003cp\u003e\u003c\/p\u003e\u003ci\u003ePractical Forensic Imaging\u003c\/i\u003e takes a detailed look at how to secure and manage digital evidence using Linux-based command line tools. This essential guide walks you through the entire forensic acquisition process and covers a wide range of practical scenarios and situations related to the imaging of storage media. \u003cp\u003e\u003c\/p\u003eYou'll learn how to: \u003cbr\u003e-Perform forensic imaging of magnetic hard disks, SSDs and flash drives, optical discs, magnetic tapes, and legacy technologies\u003cbr\u003e-Protect attached evidence media from accidental modification\u003cbr\u003e-Manage large forensic image files, storage capacity, image format conversion, compression, splitting, duplication, secure transfer and storage, and secure disposal\u003cbr\u003e-Preserve and verify evidence integrity with cryptographic and piecewise hashing, public key signatures, and RFC-3161 timestamping\u003cbr\u003e-Work with newer drive and interface technologies like NVME, SATA Express, 4K-native sector drives, SSHDs, SAS, UASP\/USB3x, and Thunderbolt\u003cbr\u003e-Manage drive security such as ATA passwords; encrypted thumb drives; Opal self-encrypting drives; OS-encrypted drives using BitLocker, FileVault, and TrueCrypt; and others\u003cbr\u003e-Acquire usable images from more complex or challenging situations such as RAID systems, virtual machine images, and damaged media \u003cp\u003e\u003c\/p\u003eWith its unique focus on digital forensic acquisition and evidence preservation, \u003ci\u003ePractical Forensic Imaging\u003c\/i\u003e is a valuable resource for experienced digital forensic investigators wanting to advance their Linux skills and experienced Linux administrators wanting to learn digital forensics. This is a must-have reference for every digital forensics lab.","brand":"No Starch Press","offers":[{"title":"Paperback","offer_id":45085843095703,"sku":"9781593277932","price":3884.0,"currency_code":"INR","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0666\/3471\/1191\/files\/9781593277932.webp?v=1769202002","url":"https:\/\/atlanticbooks.com\/products\/practical-forensic-imaging-securing-digital-evidence-with-linux-tools-9781593277932","provider":"Atlantic Books","version":"1.0","type":"link"}