Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
60 used & new from $15.41

Have one to sell? Sell yours here
 
   
Incident Response and Computer Forensics, Second Edition
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

Incident Response and Computer Forensics, Second Edition (Paperback)

by Chris Prosise (Author), Kevin Mandia (Author), Matt Pepe (Author) "Truth is stranger than fiction..." (more)
Key Phrases: Event Viewer, Internet Explorer, Security System Event (more...)
4.6 out of 5 stars See all reviews (30 customer reviews)

List Price: $52.99
Price: $33.38 & this item ships for FREE with Super Saver Shipping. Details
You Save: $19.61 (37%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
Upgrade this book for $4.99 more, and you can read, search, and annotate every page online. See details
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Monday, July 20? Choose One-Day Shipping at checkout. Details
32 new from $24.90 28 used from $15.41
Also Available in: List Price: Our Price: Other Offers:
Paperback 28 used & new from $1.50

Frequently Bought Together

Incident Response and Computer Forensics, Second Edition + Computer Forensics: Incident Response Essentials + Windows Forensic Analysis Including DVD Toolkit
Price For All Three: $121.97

Show availability and shipping details


Customers Who Bought This Item Also Bought


Editorial Reviews

Amazon.com Review
A strong system of defenses will save your systems from falling victim to published and otherwise uninventive attacks, but even the most heavily defended system can be cracked under the right conditions. Incident Response aims to teach you how to determine when an attack has occurred or is underway--they're often hard to spot--and show you what to do about it. Authors Kevin Mandia and Chris Prosise favor a tools- and procedures-centric approach to the subject, thereby distinguishing this book from others that catalog particular attacks and methods for dealing with each one. The approach is more generic, and therefore better suited to dealing with newly emerging attack techniques.

Anti-attack procedures are presented with the goal of identifying, apprehending, and successfully prosecuting attackers. The advice on carefully preserving volatile information, such as the list of processes active at the time of an attack, is easy to follow. The book is quick to endorse tools, the functionalities of which are described so as to inspire creative applications. Information on bad-guy behavior is top quality as well, giving readers knowledge of how to interpret logs and other observed phenomena. Mandia and Prosise don't--and can't--offer a foolproof guide to catching crackers in the act, but they do offer a great "best practices" guide to active surveillance. --David Wall

Topics covered: Monitoring computer systems for evidence of malicious activity, and reacting to such activity when it's detected. With coverage of Windows and Unix systems as well as non-platform-specific resources like Web services and routers, the book covers the fundamentals of incident response, processes for gathering evidence of an attack, and tools for making forensic work easier. --This text refers to an out of print or unavailable edition of this title.

Review
"... poorly trained network administrators and the lack of firewalls and intrustion detection systems still make it difficult to find the source and strategy of the attack." Computerworld article (8/21/00) on Incident Response featuring David Dittrich, a researcher who spoke at the Usenix Security Symposium." --This text refers to an out of print or unavailable edition of this title.

See all Editorial Reviews


Product Details

  • Paperback: 507 pages
  • Publisher: McGraw-Hill/Osborne; 2 edition (July 17, 2003)
  • Language: English
  • ISBN-10: 007222696X
  • ISBN-13: 978-0072226966
  • Product Dimensions: 9.1 x 7.3 x 1.2 inches
  • Shipping Weight: 2 pounds (View shipping rates and policies)
  • Average Customer Review: 4.6 out of 5 stars See all reviews (30 customer reviews)
  • Amazon.com Sales Rank: #111,544 in Books (See Bestsellers in Books)

    Popular in these categories: (What's this?)

    #13 in  Books > Computers & Internet > Security & Encryption > Forensics
    #67 in  Books > Professional & Technical > Law > Criminal Law > Criminal Procedure
    #69 in  Books > Nonfiction > Law > Criminal Law > Criminal Procedure

Inside This Book (learn more)


What Do Customers Ultimately Buy After Viewing This Item?

Incident Response and Computer Forensics, Second Edition
79% buy the item featured on this page:
Incident Response and Computer Forensics, Second Edition 4.6 out of 5 stars (30)
$33.38
File System Forensic Analysis
7% buy
File System Forensic Analysis 4.9 out of 5 stars (27)
$37.79
Mastering Windows Network Forensics and Investigation
6% buy
Mastering Windows Network Forensics and Investigation 4.8 out of 5 stars (9)
$37.79
Windows Forensic Analysis Including DVD Toolkit
4% buy
Windows Forensic Analysis Including DVD Toolkit 4.9 out of 5 stars (14)
$53.95

Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

30 Reviews
5 star:
 (23)
4 star:
 (3)
3 star:
 (3)
2 star:
 (1)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.6 out of 5 stars (30 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
32 of 33 people found the following review helpful:
5.0 out of 5 stars Ground-breaking, timely, engaging, authoritative, August 15, 2001
I am a senior engineer for network security operations. I am a graduate of the flagship session of the System Administration, Networking, and Security institute's Forensics, Investigations, and Response Education (SANS FIRE) program. "Incident Response" (IR) should have been the textbook for that program. It is the most definitive work I've read on incident response and computer forensics. I highly recommend every security professional take advantage of this book.

IR starts with a revealing case study, and follows through with additional mini-studies and "eye witness reports" based on the authors' experiences. It provides plenty of clear diagrams and charts to reinforce key points, like the innovative "hard drive layers" outlined in chapter five. Most every mention of a command line program is followed by an example of that command in action, either via screenshot or text sample. These examples let readers try similar commands on their own workstations, reinforcing the authors' investigative directions.

Beyond the excellent presentation of technical material, IR frames its discussion of incident response and computer forensics in a practical investigative methodology. My SANS FIRE training repeatedly stressed the importance of documentation, policies, processes, and methodology when performing forensic work worthy of adversarial legal scrutiny. IR's attention to detail helps investigators collect evidence in a professional, repeatable, forensically sound manner.

Having appeared in court to defend their investigations, the authors share their knowledge and emphasize crucial steps to avoid forensic pitfalls. (An example is a DOS boot floppy's interaction with the DRVSPACE.BIN file. IR explains how to avoid this issue in detail.) Falling victim to these pitfalls could give a defense attorney an easy way to clear his client, or at least make certain evidence questionable in court.

The book is not perfect. Several typos indicated somewhat rushed publication, but did not detract from technical accuracy. I would have liked more material in chapter five on file systems; perhaps another appendix would be useful?

Many books and papers describe incident response procedures for UNIX, but few dare to discuss Windows. Given the predominance of compromised Windows hosts, this book thankfully addresses the Windows response task in a complete and clear manner. In many cases UNIX and Windows are compared side-by-side, and commands for one OS are explained using equivalents for the other OS.

IR provides a durable blend of practical investigative techniques and technical insights. I predict that investigators will cite the procedures in this book as examples of "best practices" when they defend their actions in court. I plan to build my company's incident response capability around IR's recommendations.

(Disclaimer: I received my review copy free from Foundstone.)

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
20 of 22 people found the following review helpful:
5.0 out of 5 stars Another good product from the Foundstone people, June 26, 2001
By A Customer
I got an advanced copy of this book and I must say that it was not dissappointing. After reading hacking exposed, I expected usefull material from the Foundstone people and they have really come through with this book. There aren't that many good IR books out there. This has set a good standard.

Like the Hacking Exposed book, you need to sit down at a computer when reading IR. With any technical book, the real values comes with using the tools and techniques that the book describes at the computer and learning the ins and outs.

I wonder if they have the second addition already in the works?

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
16 of 18 people found the following review helpful:
5.0 out of 5 stars The best computer forensics book just got better, October 15, 2003
First, full disclosure: the publisher sent me a free review copy, I used to work for Mandia and now work with Prosise and Pepe, and I contributed material incorporated into chapters 8 and 14. I still think "Incident Response and Computer Forensics, 2nd Edition" (IRCF2E) is the best forensics book on the market. Notice I said "forensics." It's significant that the first edition's title was "Incident Response: Investigating Computer Crime." While IRCF2E contains plenty of IR material, I sense a shift away from computer security and towards the legal world in this second edition.

Readers of the first edition will want to know what's new. While reading IRCF2E I thumbed through the first edition and make some notes. The following chapters appear mostly or totally new: 1 (Real-World Incidents), 3 (Preparing for Incident Response), 4 (After Detection of an Incident), 9 (Evidence Handling), 10 (Computer System Storage Fundamentals), 11 (Data Analysis Techniques), 17 (Writing Computer Forensics Reports). Some chapters contain rewrites or new material: 2 (Intro to the IR Process), 5 (Live Data Collection from Windows), 6 (Live Data Collection from UNIX), 7 (Forensic Duplication), 8 (Collecting Network-based Evidence), and 14 (Analyzing Network Traffic). The remainder received minor rewrites. Some chapters from the first edition on IIS and application forensics were integrated elsewhere.

The most informative sections for me, as a reader of both editions, appear in chapters 7, 10, and 17. Chapter 7 lays down the law on differences between a "forensic duplication," a "qualified forensic duplication," and a "mirror image." Expert witnesses can turn to IRCF2E as a standard when testifying, thanks to this chapter's clarity and citations of "Daubert" and "Kumho." Chapter 10 nicely explains file systems and storage layers. Chapter 17 gives desperately needed guidance on writing forensics reports -- the part of an engagement the client really wants.

I found a few errata items, such as p. 61's reference to the PPA; it should be "Privacy Protection Act." On pp. 97-98, all of the "ps" tools should list the Sysinternals home page, not Foundstone. Despite my contribution of material to the network-oriented chapters of IRCF2E, don't believe that I advocate using laptops for monitoring duties (p. 179). Laptops and especially their NIC drivers are not built for packet capture in high speed environments.

IRCF2E is one of the few books in print where the word "forensics" deserves to be on the cover. Many prominent "forensics" titles deliver nothing useful to practitioners. As was the case with the first edition, investigators can use IRCF2E in operational environments to do real work. This book lays much of the groundwork for doing cases. Watch for "Real Digital Forensics" to be published next year, which walks readers through case-based evidence to teach how to collect, interpret, and analyze host- and network-based evidence.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
Ad
 
Most Recent Customer Reviews

4.0 out of 5 stars Still Relevant and an Excellent book
Must have been 5 years ago or so when I first bought this book. I have been using it ever since. This is not a Forensics book, but it is a nice marketing ploy to add it into the... Read more
Published 25 days ago by Viken Derderian

5.0 out of 5 stars You must buy...
You must buy if you are beginner, intermedium or advanced in forensic computers.
Published on January 16, 2007 by Dino

3.0 out of 5 stars Ok book but File System Forensic is better
I liked this book, but it is scattered in its topics. A lot of the information can be found online, and the tools aren't what we use on a daily basis. Read more
Published on May 24, 2006 by Rob DePena, CCSE

5.0 out of 5 stars Best incidence reponse book out
This is no doubt the best incidence reponse book out. I highly recommend this for anyone either in the field, learning to get into the field, or running a small to medium sized... Read more
Published on March 3, 2005 by David Trube

4.0 out of 5 stars Excellent basic reference
I read the book in about three days and found it to be a good primer for one leaning towards computer forensics. Read more
Published on May 14, 2004 by Brian Saloum

5.0 out of 5 stars The Very Best Computer Forensics Primer Out There (1/04)
As an attorney and a formally-trained computer forensics examiner and instructor who has been tilling the fields of digital evidence for some time, I'm always on the prowl for the... Read more
Published on January 21, 2004 by Craig Ball

2.0 out of 5 stars mediocre
The book gives a decent overview on the field, but lacks technical accuracy. The authors fumble on technical details. Read more
Published on November 28, 2003 by Justin Gombos

5.0 out of 5 stars Best IR book
This is a great book.

I think it is the best incident response book available.

These guys really know their stuff and the book has a ton of good information. Read more

Published on November 20, 2003 by Eric Kent

5.0 out of 5 stars A revealing and authoritative instructional reference
Now in an updated and expanded second edition, Incident Response & Computer Forensics (007222696X; 544 pages; $49. Read more
Published on November 13, 2003 by Midwest Book Review

5.0 out of 5 stars Very useful, comprehensive and fun to read
This is my review for the Second Edition.

Incident Response is back with a vengeance! I should disclose that I was very impressed with the first edition, for many reasons. Read more

Published on October 24, 2003 by Dr Anton Chuvakin

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]


Active discussions in related forums
   


Product Information from the Amapedia Community

Beta (What's this?)


So You'd Like to...


Look for Similar Items by Category


Smooth Operator

Shop for garage door openers

Find garage door products (opener kits, remotes, mini-key-chain controls, and wireless-key entry systems) in the Hardware Store. Opening the garage door shouldn’t be a chore.

Shop all garage door hardware

 

Big Savings in Books

Bargain Books
Find great titles at fantastic prices in our Bargain Books Store.
 

Buy Three Books, Get a Fourth Free

4-for-3 Books
Order any four eligible books under $10 and get the lowest-price book free in our 4-for-3 Books Store. See more details.
 

Best Books

Best of the Month
See our editors' picks and more of the best new books on our Best of the Month page.
 
Ad

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Free
Free by Chris Anderson
Paranoia
Paranoia by Joseph Finder
My Soul to Lose
My Soul to Lose by Rachel Vincent
Glenn Beck's Common Sense

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates