My Account Log in

3 options

Python digital forensics cookbook : effective Python recipes for digital investigations / Preston Miller, Chapin Bryce.

EBSCOhost Academic eBook Collection (North America) Available online

View online

Ebook Central College Complete Available online

View online

O'Reilly Online Learning: Academic/Public Library Edition Available online

View online
Format:
Book
Author/Creator:
Miller, Preston, author.
Bryce, Chapin, author.
Language:
English
Subjects (All):
Python (Computer program language).
Physical Description:
1 online resource (1 volume) : illustrations
Edition:
1st edition
Place of Publication:
Birmingham, England : Packt, 2017.
System Details:
text file
Biography/History:
Bryce Chapin: Chapin Bryce is a senior consultant at a global firm that is a leader in digital forensics and incident response investigations. After graduating from Champlain College, with a bachelor's degree in computer and digital forensics, Chapin dove into the field of digital forensics and incident response joining the GIAC advisory board and earning four GIAC certifications: GCIH, GCFE, GCFA, and GNFA. As a member of multiple ongoing research and development projects, he has authored several books and articles in professional and academic publications, including Python Digital Forensics Cookbook (2018 Digital Forensics Book of the Year, Forensic 4Cast), Learning Python for Forensics First Edition, and Digital Forensic Magazine. Miller Preston: Preston Miller is a consultant at an internationally recognized risk management firm. Preston holds an undergraduate degree from Vassar College and a master's degree in digital forensics from Marshall University. While at Marshall, Preston unanimously received the prestigious J. Edgar Hoover Foundation's scientific scholarship. Preston is a published author, recently of Python Digital Forensics Cookbook, which won the Forensic 4: cast Digital Forensics Book of the Year award in 2018. Preston is a member of the GIAC advisory board and holds multiple industry-recognized certifications in his field.
Summary:
Over 60 recipes to help you learn digital forensics and leverage Python scripts to amplify your examinations About This Book Develop code that extracts vital information from everyday forensic acquisitions. Increase the quality and efficiency of your forensic analysis. Leverage the latest resources and capabilities available to the forensic community. Who This Book Is For If you are a digital forensics examiner, cyber security specialist, or analyst at heart, understand the basics of Python, and want to take it to the next level, this is the book for you. Along the way, you will be introduced to a number of libraries suitable for parsing forensic artifacts. Readers will be able to use and build upon the scripts we develop to elevate their analysis. What You Will Learn Understand how Python can enhance digital forensics and investigations Learn to access the contents of, and process, forensic evidence containers Explore malware through automated static analysis Extract and review message contents from a variety of email formats Add depth and context to discovered IP addresses and domains through various Application Program Interfaces (APIs) Delve into mobile forensics and recover deleted messages from SQLite databases Index large logs into a platform to better query and visualize datasets In Detail Technology plays an increasingly large role in our daily lives and shows no sign of stopping. Now, more than ever, it is paramount that an investigator develops programming expertise to deal with increasingly large datasets. By leveraging the Python recipes explored throughout this book, we make the complex simple, quickly extracting relevant information from large datasets. You will explore, develop, and deploy Python code and libraries to provide meaningful results that can be immediately applied to your investigations. Throughout the Python Digital Forensics Cookbook, recipes include topics such as working with forensic evidence containers, parsing mobile and desktop operating system artifacts, extracting embedded metadata from documents and executables, and identifying indicators of compromise. You will also learn to integrate scripts with Application Program Interfaces (APIs) such as VirusTotal and PassiveTotal, and tools such as Axiom, Cellebrite, and EnCase. By the end of the book, you will have a sound understanding of Python and how you can use it to process artifacts in your investigations. Style and approach Our succinct recipes take a no-...
Contents:
Cover
Copyright
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Customer Feedback
Dedication
Table of Contents
Preface
Chapter 1: Essential Scripting and File Information Recipes
Introduction
Handling arguments like an adult
Getting started
How to do it…
How it works…
There's more…
Iterating over loose files
Recording file attributes
Copying files, attributes, and timestamps
Hashing files and data streams
Keeping track with a progress bar
Logging results
Multiple hands make light work
Chapter 2: Creating Artifact Report Recipes
Using HTML templates
How to do it...
How it works...
There's more...
Creating a paper trail
Working with CSVs
Visualizing events with Excel
Auditing your work
Chapter 3: A Deep Dive into Mobile Forensic Recipes
Parsing PLIST files
Handling SQLite databases
Identifying gaps in SQLite databases.
Getting started
See also
Processing iTunes backups
Putting Wi-Fi on the map
Digging deep to recover messages
Chapter 4: Extracting Embedded Metadata Recipes
Extracting audio and video metadata
The big picture
Mining for PDF metadata
Reviewing executable metadata
Reading office document metadata
Integrating our metadata extractor with EnCase
Chapter 5: Networking and Indicators of Compromise Recipes
Getting a jump start with IEF
Coming into contact with IEF
Beautiful Soup
Going hunting for viruses
Gathering intel
Totally passive
Chapter 6: Reading Emails and Taking Names Recipes
Parsing EML files
Viewing MSG files
How to do it.
How it works...
Ordering Takeout
What's in the box?!
Parsing PST and OST mailboxes
Chapter 7: Log-Based Artifact Recipes
About time
Parsing IIS web logs with RegEx
Going spelunking
Interpreting the daily.out log
Adding daily.out parsing to Axiom
Scanning for indicators with YARA
Chapter 8: Working with Forensic Evidence Container Recipes
Opening acquisitions
Gathering acquisition and media information
Iterating through files
Processing files within the container
Searching for hashes
Chapter 9: Exploring Windows Forensic Artifacts Recipes - Part I
One man's trash is a forensic examiner's treasure
A sticky situation
Reading the registry
Gathering user activity
The missing link
Searching high and low
Chapter 10: Exploring Windows Forensic Artifacts Recipes - Part II
Parsing prefetch files
A series of fortunate events
Indexing internet history
Shadow of a former self
Dissecting the SRUM database
Conclusion
Index.
Notes:
Includes index.
Description based on online resource; title from PDF title page (ebrary, viewed October 6, 2017).
OCLC:
1007536293

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account