Legal Cyber Academy
BookPaidCurrent

Hiding Behind the Keyboard: Uncovering Covert Communication Methods with Forensic Analysis

Brett Shavers, John Bair · Syngress (Elsevier) · First edition · 2016

Identifier: ISBN 978-0-12-803340-1

Access and status

Cost

Paid

Costs money to buy outright — a book, a licence, a registration.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

A survey of covert communication methods an investigator will run into — Tor and TAILS, steganography, encrypted messaging, anti-forensic tooling — and what each one leaves behind on a device.

Who it is for, and when

Useful when a case turns on a channel you cannot read directly and you need to know which side-channel artifacts survive: installation traces, configuration files, prefetch and registry residue, mobile app containers. Also useful for setting expectations with counsel about what encryption does and does not foreclose.

What it does not cover

The specific tool and protocol detail has moved on fastest of anything in this book: the Tor Browser, TAILS and mobile messaging apps described are several major versions out of date, and it predates the shift to default end-to-end encryption and ephemeral messaging in mainstream apps.

Go to the source

Open at shop.elsevier.com (opens in a new tab)

https://shop.elsevier.com/books/hiding-behind-the-keyboard/shavers/978-0-12-803340-1

Details

Type
Book
Written for
Working examinerWorking examiner
Author
Brett Shavers, John Bair
Publisher
Syngress (Elsevier)
Version verified
First edition
Year
2016
Identifier
ISBN 978-0-12-803340-1
Topics
anti-forensics, encryption, network, mobile
Checked at source
  • A public repository of forensic disk images, memory dumps, mobile extractions, network packet captures and file corpora assembled for forensic research and teaching. The data is held in Amazon S3 (s3://digitalcorpora/) under the AWS Open Data Sponsorship Program and served from downloads.digitalcorpora.org.

  • NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.

  • SWGDE's guidance on analysing historical call detail records and cell site data to reason about where a handset was, and on the limits of that reasoning. The version verified here is 17-F-001-5.0 dated 9 July 2026; it has moved through four earlier versions since 2023, including a retitling from Recommendations to Best Practices.

  • The post-conference edited volumes of the annual IFIP Working Group 11.9 International Conference on Digital Forensics, published by Springer as the numbered Advances in Digital Forensics series. Volume XX covers the twentieth conference and appeared in 2025; the working group's site lists the twenty-third conference for January 2027, so the series is live.

  • A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.