Legal Cyber Academy
BookPaidCurrent

Incident Response & Computer Forensics

Jason T. Luttgens, Matthew Pepe, Kevin Mandia (with Ryan Kazanciyan) · McGraw-Hill Education · Third edition · 2014

Identifier: ISBN 978-0-07-179868-6

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.

Who it is for, and when

Read it for the process rather than the tools — the scoping discipline, the distinction between collection and analysis, and the insistence that an investigation produce a written, defensible result. The chapters on evidence handling and on report writing are the ones most often skipped and most often needed when the matter turns into litigation.

What it does not cover

Published in 2014 and pre-cloud in its assumptions: nothing on SaaS and IaaS log sources, identity-provider evidence, EDR-centric collection, containers, or ransomware as the dominant incident type. Windows and Unix host focus. No fourth edition exists and McGraw Hill no longer carries a live product page for it, so the tooling must be replaced wholesale even where the method holds; this entry is verified against the Library of Congress record.

Go to the source

Open at lccn.loc.gov (opens in a new tab)

https://lccn.loc.gov/2015460939

Details

Type
Book
Written for
Working examinerWorking examiner
Author
Jason T. Luttgens, Matthew Pepe, Kevin Mandia (with Ryan Kazanciyan)
Publisher
McGraw-Hill Education
Version verified
Third edition
Year
2014
Identifier
ISBN 978-0-07-179868-6
Topics
incident-response, evidence-handling, triage, reporting, network, log-analysis
Checked at source
  • A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.

  • Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.

  • Antisyphon runs selected courses on a Pay What You Can model, stating that it wants to help people who cannot afford conventional training prices. Courses confirmed on the page at the time of checking are SOC Core Skills in the Age of AI with John Strand (live and on-demand) and the Professionally Evil CISSP Mentorship Program (live, multiple instructors).

  • An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.

  • A Kroll-owned Windows triage tool that collects forensically relevant files from a live or mounted system using configurable Targets, then runs parsers over what it collected using Modules. It bypasses file locks with raw disk reads and preserves original timestamps on the copies.