/ Linux Forensics - Paperback

Linux Forensics - Paperback

Regular price$66.15
/
(Tax included. Shipping calculated at checkout.)
✔ Authenticity Guaranteed — Verified Designer Goods
✔ 100% Money-Back Guarantee on Eligible Items
✔ Prices Displayed in Your Local Currency
✔ Final Price = No Surprise Import Fees
✔ Complimentary Insured Worldwide Shipping on Qualifying Orders
✔ Select Collector & Specialty Pieces May Require Secured Delivery Handling
Our authentication process ensures every item meets strict luxury verification standards. Learn more
Complimentary worldwide shipping on qualifying orders

by Philip Polstra (Author)

Linux Forensics is the most comprehensive and up-to-date resource for those wishing to quickly and efficiently perform forensics on Linux systems. It is also a great asset for anyone that would like to better understand Linux internals.

Linux Forensics will guide you step by step through the process of investigating a computer running Linux. Everything you need to know from the moment you receive the call from someone who thinks they have been attacked until the final report is written is covered in this book. All of the tools discussed in this book are free and most are also open source.

Dr. Philip Polstra shows how to leverage numerous tools such as Python, shell scripting, and MySQL to quickly, easily, and accurately analyze Linux systems. While readers will have a strong grasp of Python and shell scripting by the time they complete this book, no prior knowledge of either of these scripting languages is assumed. Linux Forensics begins by showing you how to determine if there was an incident with minimally invasive techniques. Once it appears likely that an incident has occurred, Dr. Polstra shows you how to collect data from a live system before shutting it down for the creation of filesystem images.

Linux Forensics contains extensive coverage of Linux ext2, ext3, and ext4 filesystems. A large collection of Python and shell scripts for creating, mounting, and analyzing filesystem images are presented in this book. Dr. Polstra introduces readers to the exciting new field of memory analysis using the Volatility framework. Discussions of advanced attacks and malware analysis round out the book.

Book Highlights

  • 370 pages in large, easy-to-read 8.5 x 11 inch format
  • Over 9000 lines of Python scripts with explanations
  • Over 800 lines of shell scripts with explanations
  • A 102 page chapter containing up-to-date information on the ext4 filesystem
  • Two scenarios described in detail with images available from the book website
  • All scripts and other support files are available from the book website

Chapter Contents

  1. First Steps
    • General Principles
    • Phases of Investigation
    • High-level Process
    • Building a Toolkit
  2. Determining If There Was an Incident
    • Opening a Case
    • Talking to Users
    • Documenation
    • Mounting Known-good Binaries
    • Minimizing Disturbance to the Subject
    • Automation With Scripting
  3. Live Analysis
    • Getting Metadata
    • Using Spreadsheets
    • Getting Command Histories
    • Getting Logs
    • Using Hashes
    • Dumping RAM
  4. Creating Images
    • Shutting Down the System
    • Image Formats
    • DD
    • DCFLDD
    • Write Blocking
    • Imaging Virtual Machines
    • Imaging Physical Drives
  5. Mounting Images
    • Master Boot Record Based Partions
    • GUID Partition Tables
    • Mounting Partitions In Linux
    • Automating With Python
  6. Analyzing Mounted Images
    • Getting Timestamps
    • Using LibreOffice
    • Using MySQL
    • Creating Timelines
  7. Extended Filesystems
    • Basics
    • Superblocks
    • Features
    • Using Python
    • Finding Things That Are Out Of Place
    • Inodes
    • Journaling
  8. Memory Analysis
    • Volatility
    • Creating Profiles
    • Linux Commands
  9. Dealing With More Advanced Attackers
  10. Malware
    • Is It Malware?
    • Malware Analysis Tools
    • Static Analysis
    • Dynamic Analysis
    • Obfuscation
  11. The Road Ahead
    • Learning More
    • Communities
    • Conferences
    • Certifications

Author Biography

Dr. Philip Polstra (known to his friends as Dr. Phil) is an internationally recognized hardware hacker. His work has been presented at numerous conferences around the globe including repeat performances at DEFCON (six presentations in four years), BlackHat, 44CON, GrrCON, MakerFaire, ForenSecure, and other top conferences. Dr. Polstra is a well-known expert on USB forensics and has published several articles on this topic. He has developed a number of video courses including ones on Linux forensics, USB forensics, and reverse engineering.

Dr. Polstra has developed degree programs in digital forensics and ethical hacking while serving as a professor and Hacker in Residence at a private university in the Midwestern United States. He currently teaches in one of the top Digital Forensics degree programs in the United States at Bloomsburg University of Pennsylvania. In addition to teaching, he provides training and performs penetration tests on a consulting basis. When not working, he has been known to fly, build aircraft, and tinker with electronics. He is an accomplished aviator with thousands of hours of flight time and a dozen ratings as a pilot, flight instructor, mechanic, aircraft inspector, and avionics specialist. His latest happenings can be found on his website http: //philpolstra.com. You can also follow him at @ppolstra on Twitter.

Dr. Polstra authored Hacking and Penetration Testing with Low Power Devices (Syngress, 2014) in which he showed the world how to easily build drop boxes, hacking consoles, and remote hacking drones with the BeagleBone Black and similar devices. In the course of creating these devices he developed his own Linux, Deck Linux, which is optimized for security testing with ARM-based devices. Techniques described in this book permit security penetration tests to be performed with multiple, possibly battery powered, devices which are controlled by a user up to two miles away from the target organization.

His latest book, Linux Forensics (Pentester Academy, 2015), is the most comprehensive and up-to-date resource available to anyone wishing to perform forensics on Linux systems. The first printing of this book sold out in under twenty five hours. This book is considered a must have by a number of forensic investigators around the world.

Number of Pages: 370
Dimensions: 0.77 x 11.02 x 8.5 IN
Publication Date: July 13, 2015
  • In stock, ready to ship
  • Backordered, shipping soon
Shop with Confidence
  • ✔ Authenticity Guaranteed — Verified Designer Goods
  • ✔ Sourced from Authorized European/U.S. Luxury Distributors
  • ✔ Secure Checkout — SSL Encrypted Payments
  • ✔ Fast Global Delivery — 3–11 Business Days
  • ✔ Easy Returns on Eligible Items
  • ✔ 100% Money-Back Guarantee — Full Refund if Not Satisfied
Verified Trust Rating: 91/100
Amazon American Express Apple Pay Bancontact Diners Club Discover Google Pay Mastercard PayPal Shop Pay USDC Visa SSL Secure
Amazon Pay Logo Fast checkout with Amazon Pay. Use your Amazon account to skip entering shipping or card info.
Trusted by discerning buyers worldwide — secure, verified luxury sourcing

AUTHENTICITY GUARANTEED

Reserved for you — complete your purchase to secure this piece.

Authorized Designer Inventory Secure & Encrypted Checkout Tracked & Insured Delivery

OFFICIALLY AUTHORIZED RESELLER

Discover Officially Authorized Authentic Items at STORE7994.com - Certificates Available on Request!

Independently verified for store quality and customer safety.
Trust score: 91/100

All designer items offered by STORE 7994 are sourced from trusted luxury distributors and verified through independent authentication services.

Learn how STORE 7994 authenticates luxury items

Guaranteed Authentic — Includes Brand Documentation & Third-Party Verification Options.

Shipping information

  • Free Shipping* on all orders over $300 USD to most countries* Estimated delivery: 2-5 business days Mon-Sat to U.S., CA, EU etc.
  • Tracking available: DHL Express
  • Store 7994 Shipping policy
  • Global delivery in 3–9 business days (location dependent).
  • Free Worldwide Shipping $300+. International duties & VAT are calculated by destination country and may be collected upon delivery. UK orders are subject to 20% import VAT upon delivery.

Our innovation isn’t just in the brands we carry — it’s in the way we connect them. From our automation engine that keeps collections globally updated to our commitment to authenticity-first presentation, STORE 7994 exists where timeless design meets modern precision.

Every product we offer is:
Elevated · Intentional · Exclusive · Authentic

STORE 7994 is an authorized reseller of luxury fashion houses. Certificates and proof of authenticity are available to brand owners and partners upon request.

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.

Returns & Refunds

We want you to shop with confidence at STORE 7994. If your purchase does not meet expectations, eligible items may be returned under the conditions below.

Return Eligibility
Items must be unused, unworn, and in original condition with all tags, packaging, and accessories included. Items showing any signs of wear or damage will not be accepted.

Return Window
Return requests must be made within 14 days of delivery.

Return Shipping
Customers are responsible for return shipping costs unless the item is defective, damaged, or incorrect.

Luxury Items
Items valued over $1,000 may be subject to a 7% restocking fee upon approved return.

Non-Returnable Items
For hygiene and product integrity reasons, the following items are final sale once opened or used:

• Underwear
• Fragrances
• Any worn or used items

Made-to-Order Items
Custom-designed products, including STORE 7994 hoodies, are made exclusively for each customer and are final sale. These items are not eligible for return or exchange unless defective or incorrect.

If you receive a defective or incorrect item, please contact us and we will make it right.

International Shipping & Duties
Many of our products ship directly from trusted international partners. Any applicable customs duties or import taxes are calculated at checkout and are non-refundable, even if the item is returned.

Returns & Associated Fees
All approved returns are subject to a $24 return processing fee. For international orders, duties, taxes, and return fees will be deducted from the original payment.

Shipping Policy
Complimentary shipping is offered on orders over $300. Orders below this threshold are subject to standard shipping rates at checkout.