Chapter 20: Creating a Bootable Environment and Live Response Tool Kit

OVERVIEW

When a call comes in that a system has been hacked, the forensic consultant has to be ready to move quickly. Sometimes, the victim system will be so badly damaged by the attack that the machine won't even be able to boot. Some victim systems may be functional, but the "powers that be" will allow the victim to be taken offline to perform proper analysis on it. Still others, however, will require that the system remain online while the analysis is performed. No matter what the scenario, the forensic consultant has to be prepared to deal with it from an incident response perspective.

In this chapter, we'll tell you how to create a bootable incident response media (usually either CD-ROM or floppy) that contains all the tools you'll need to perform a proper incident response analysis to an attack. We'll also put together a collection of critical Windows and Unix tools that can be used for forensic analysis on live systems.



Anti-Hacker Tool Kit
Anti-Hacker Tool Kit, Third Edition
ISBN: 0072262877
EAN: 2147483647
Year: 2006
Pages: 175

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net