Digital Forensics and Incident Response: Incident Response Tools and Techniques for Effective Cyber Threat Response
Gerard Johansen · Packt Publishing · Third edition · 2022
Identifier: ISBN 978-1-80323-867-8
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.
Who it is for, and when
The most current single volume that treats examination and response as one job rather than two. Read it if your work sits in a corporate environment where the deliverable is a scoping answer under time pressure, and read the ransomware material if you are advising on an active matter.
What it does not cover
Breadth over depth — each technical area gets a working introduction, not the structural detail that Carrier, Ligh or Nikkel provide, so it will not carry you through a contested technical dispute. Light on cloud-native and identity evidence, which is exactly what a fourth edition is meant to address; that edition is listed by Packt as a pre-order and is not published, so the third edition remains current.
Go to the source
Open at packtpub.com (opens in a new tab)https://www.packtpub.com/en-us/product/digital-forensics-and-incident-response-9781803238678
Details
- Type
- Book
- Written for
- Working examinerWorking examiner
- Author
- Gerard Johansen
- Publisher
- Packt Publishing
- Version verified
- Third edition
- Year
- 2022
- Identifier
- ISBN 978-1-80323-867-8
- Topics
- incident-response, triage, memory-forensics, threat-hunting, reporting, network
- Checked at source
Related entries
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.
CyberDefenders
Partly freeA blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
FIRST Conference
PaidThe annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.
A short daily audio briefing, typically five to ten minutes, summarising the Internet Storm Center diaries and the day's notable vulnerabilities and exploitation activity.