Legal Cyber Academy
BookPaidCurrent

Digital Forensics and Incident Response: Incident Response Tools and Techniques for Effective Cyber Threat Response

Gerard Johansen · Packt Publishing · Third edition · 2022

Identifier: ISBN 978-1-80323-867-8

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.

Who it is for, and when

The most current single volume that treats examination and response as one job rather than two. Read it if your work sits in a corporate environment where the deliverable is a scoping answer under time pressure, and read the ransomware material if you are advising on an active matter.

What it does not cover

Breadth over depth — each technical area gets a working introduction, not the structural detail that Carrier, Ligh or Nikkel provide, so it will not carry you through a contested technical dispute. Light on cloud-native and identity evidence, which is exactly what a fourth edition is meant to address; that edition is listed by Packt as a pre-order and is not published, so the third edition remains current.

Go to the source

Open at packtpub.com (opens in a new tab)

https://www.packtpub.com/en-us/product/digital-forensics-and-incident-response-9781803238678

Details

Type
Book
Written for
Working examinerWorking examiner
Author
Gerard Johansen
Publisher
Packt Publishing
Version verified
Third edition
Year
2022
Identifier
ISBN 978-1-80323-867-8
Topics
incident-response, triage, memory-forensics, threat-hunting, reporting, network
Checked at source
  • A gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.

  • The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.

  • CyberDefenders

    Partly free

    A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.

  • The annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.

  • A short daily audio briefing, typically five to ten minutes, summarising the Internet Storm Center diaries and the day's notable vulnerabilities and exploitation activity.