Part 7

Reverse Engineering for Security Investigations

Reconstruct activity from incomplete evidence

Combine binaries with core files, memory captures, logs, network records and recovered configuration. Investigate what ran, what data may have been accessed and which sequence of events fits the evidence. Develop timelines, test competing explanations and distinguish an implemented capability from its actual use.

0 Chapter

HackerBoost

Subscriptions coming soon

We are preparing the HackerBoost library. You can create an account now; subscriptions will open later.

Sign in to read the first three chapters of the first part for free.

Contents