Book description
The book Executing Windows Command Line Investigations targets the needs of cyber security practitioners who focus on digital forensics and incident response. These are the individuals who are ultimately responsible for executing critical tasks such as incident response; forensic analysis and triage; damage assessments; espionage or other criminal investigations; malware analysis; and responding to human resource violations.
The authors lead readers through the importance of Windows CLI, as well as optimal configuration and usage. Readers will then learn the importance of maintaining evidentiary integrity, evidence volatility, and gain appropriate insight into methodologies that limit the potential of inadvertently destroying or otherwise altering evidence. Next, readers will be given an overview on how to use the proprietary software that accompanies the book as a download from the companion website. This software, called Proactive Incident Response Command Shell (PIRCS), developed by Harris Corporation provides an interface similar to that of a Windows CLI that automates evidentiary chain of custody and reduces human error and documentation gaps during incident response.
- Includes a free download of the Proactive Incident Response Command Shell (PIRCS) software
- Learn about the technical details of Windows CLI so you can directly manage every aspect of incident response evidence acquisition and triage, while maintaining evidentiary integrity
Table of contents
- Cover image
- Title page
- Table of Contents
- Copyright
- Dedication
- Biography
- Foreword
- Preface
- Acknowledgments
- Harris Corporation
- Chapter 1: The Impact of Windows Command Line Investigations
- Chapter 2: Importance of Digital Evidence Integrity
- Chapter 3: Windows Command Line Interface
- Chapter 4: Operating the Proactive Incident Response Command Shell
- Chapter 5: Use Cases
- Chapter 6: Future Considerations
- Appendix A: Third-party Windows CLI Tools
- Appendix B: Windows CLI Reference Synopsis
- Index
Product information
- Title: Executing Windows Command Line Investigations
- Author(s):
- Release date: June 2016
- Publisher(s): Syngress
- ISBN: 9780128092712
You might also like
book
How to Cheat at Windows System Administration Using Command Line Scripts
How to Cheat at Windows Systems Administrators using Command Line Scripts teaches system administrators hundreds of …
book
Windows® Command-Line Administration: Instant Reference
The perfect companion to any book on Windows Server 2008 or Windows 7, and the quickest …
book
Windows 10 for Enterprise Administrators
Tag line About This Book Learn the art of configuring, deploying, managing and securing Windows 10 …
book
Windows® Command-Line Administrators Pocket Consultant, Second Edition
Now updated for Windows Server 2008 and Windows Vista, this practical, pocket-sized reference delivers ready answers …