Windows Forensics and Incident Recovery

本书专注于Windows环境下的取证及事件恢复技术,通过案例研究和实际应用实例教授读者如何识别并响应各种攻击事件。覆盖了从Windows Server 2003到Windows XP等多个版本,并提供了一套完整的事件响应工具集。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

*The first book to focus on forensics and incident recovery in a Windows environment
*Teaches through case studies and real world-examples
*Covers Windows Server 2003, Windows 2000, Windows NT, and Windows XP

If you're responsible for protecting Windows systems, firewalls and anti-virus aren't enough. You also need to master incident response, recovery, and auditing. Leading Windows security expert and instructor Harlan Carvey offers a start-to-finish guide to the subject: everything administrators must know to recognize and respond to virtually any attack.

Drawing on his widely acclaimed course, Carvey uses real-world examples to cover every significant incident response, recovery, and forensics technique. He delivers a complete incident response toolset that combines today's best open source and freeware tools, his own exclusive software and scripts, and step-by-step instructions for using them. This book's tools and techniques apply to every current and professional version of Windows: NT, 2000, XP, and Windows Server 2003. Coverage includes:

*Developing a practical methodology for responding to potential attacks
*Preparing your systems to prevent and detect incidents
*Recognizing the signatures of an attackin time to act
*Uncovering attacks that evade detection by Event Viewer, Task Manager, and other Windows GUI tools
*Using the Forensic Server Project to automate data collection during live investigations
*Analyzing live forensics data in order to determine what occurred

http://rapidshare.com/files/40489622/0321200985.rar
http://depositfiles.com/files/1136715
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值