Hiding Behind the Keyboard: Uncovering Covert Communication Methods with Forensic Analysis
Brett Shavers, John Bair · Syngress (Elsevier) · First edition · 2016
Identifier: ISBN 978-0-12-803340-1
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
A survey of covert communication methods an investigator will run into — Tor and TAILS, steganography, encrypted messaging, anti-forensic tooling — and what each one leaves behind on a device.
Who it is for, and when
Useful when a case turns on a channel you cannot read directly and you need to know which side-channel artifacts survive: installation traces, configuration files, prefetch and registry residue, mobile app containers. Also useful for setting expectations with counsel about what encryption does and does not foreclose.
What it does not cover
The specific tool and protocol detail has moved on fastest of anything in this book: the Tor Browser, TAILS and mobile messaging apps described are several major versions out of date, and it predates the shift to default end-to-end encryption and ephemeral messaging in mainstream apps.
Go to the source
Open at shop.elsevier.com (opens in a new tab)https://shop.elsevier.com/books/hiding-behind-the-keyboard/shavers/978-0-12-803340-1
Details
- Type
- Book
- Written for
- Working examinerWorking examiner
- Author
- Brett Shavers, John Bair
- Publisher
- Syngress (Elsevier)
- Version verified
- First edition
- Year
- 2016
- Identifier
- ISBN 978-0-12-803340-1
- Topics
- anti-forensics, encryption, network, mobile
- Checked at source
Related entries
Digital Corpora
FreeA public repository of forensic disk images, memory dumps, mobile extractions, network packet captures and file corpora assembled for forensic research and teaching. The data is held in Amazon S3 (s3://digitalcorpora/) under the AWS Open Data Sponsorship Program and served from downloads.digitalcorpora.org.
NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.
SWGDE's guidance on analysing historical call detail records and cell site data to reason about where a handset was, and on the limits of that reasoning. The version verified here is 17-F-001-5.0 dated 9 July 2026; it has moved through four earlier versions since 2023, including a retitling from Recommendations to Best Practices.
The post-conference edited volumes of the annual IFIP Working Group 11.9 International Conference on Digital Forensics, published by Springer as the numbered Advances in Digital Forensics series. Volume XX covers the twentieth conference and appeared in 2025; the working group's site lists the twenty-third conference for January 2027, so the series is live.
A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.