Legal Cyber Academy
BookPaidCurrent

Forensic Discovery

Dan Farmer, Wietse Venema · Addison-Wesley Professional · First edition · 2004

Identifier: ISBN 978-0-201-63497-6

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A short, dense book about the physics of digital evidence: the order of volatility, how long deleted data actually persists, what abstraction layers hide, and how to reason about an adversary who has had root. Examples come from Solaris, FreeBSD and Linux.

Who it is for, and when

Read it for the concepts that later books borrowed without attribution — volatility ordering, the decay curve of deleted data, and the idea that every tool you run is itself an abstraction that can lie to you. Useful to anyone who has to justify why live acquisition was or was not appropriate in a given case.

What it does not cover

Twenty years old and Unix-centric: no Windows, no mobile, no cloud, no modern encryption, and the persistence measurements were taken on spinning disks with no TRIM. The reasoning is durable; every empirical number in it should be treated as historical.

Go to the source

Open at informit.com (opens in a new tab)

https://www.informit.com/store/forensic-discovery-9780201634976

Details

Type
Book
Written for
AdvancedAdvanced
Author
Dan Farmer, Wietse Venema
Publisher
Addison-Wesley Professional
Version verified
First edition
Year
2004
Identifier
ISBN 978-0-201-63497-6
Topics
foundations, linux, evidence-handling, anti-forensics, memory-forensics
Checked at source
  • 13Cubed

    Partly free

    A YouTube channel and companion training site covering Windows, Linux and macOS endpoint forensics, memory analysis and threat hunting. The YouTube videos are free; the on-demand courses on training.13cubed.com are paid.

  • A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.

  • Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.

  • FTK Imager

    Partly free

    A free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.

  • NIST's guidance on clearing, purging and destroying data on storage media, including media-specific techniques and verification. Revision 2 was published in September 2025 and supersedes Revision 1 (2014), which NIST withdrew on 26 September 2025.