IPS, IDS, and SIEM

IPS, IDS, and SIEM

Computer Forensics 3 views 0 downloads
Language English
'IPS, IDS, and SIEM' delivers an authoritative, methodical framework for digital evidence acquisition, forensic examination, and cybercrime investigation. Emphasizing legal admissibility, forensic soundess, and rigorous chain of custody, this volume covers the full lifecycle of a digital investigation.

Key topics include physical disk imaging, file system analysis (NTFS, EXT4), Windows artifact examination (Registry, Prefetch, Event Logs), volatile RAM memory capture and analysis, network packet dissection, browser history extraction, and forensic report writing. Workflows utilizing Autopsy, FTK Imager, and EnCase are detailed.

An indispensable handbook for digital forensic examiners, incident response specialists, corporate investigators, and law enforcement analysts.
Contents at a Glance
Chapter 1: Introduction to SIEM Architecture and Splunk Core
Chapter 2: Data Ingestion: Forwarders, Inputs, and Source Types
Chapter 3: Searching and Filtering Data with Search Processing Language (SPL)
Chapter 4: Creating Knowledge Objects: Field Extractions, Tags, and Event Types
Chapter 5: Designing SOC Dashboards, Visualizations, and Alerts
Chapter 6: Splunk for Incident Investigation: Correlating Multi-Source Logs
Chapter 7: Building Detection Rules Aligned with MITRE ATT&CK
Chapter 8: Splunk Enterprise Security (ES) and Threat Intelligence Frameworks
Index & Further Reading