Jump to ratings and reviews
Rate this book

Incident Response & Computer Forensics, Third Edition

Rate this book
Publisher's Note: Products purchased from Third Party sellers are not guaranteed by the publisher for quality, authenticity, or access to any online entitlements included with the product. The definitive guide to incident response--updated for the first time in a decade! Thoroughly revised to cover th ...

ebook

First published July 6, 2013

79 people are currently reading
325 people want to read

About the author

Ratings & Reviews

What do you think?
Rate this book

Friends & Following

Create a free account to discover what your friends think of this book!

Community Reviews

5 stars
59 (52%)
4 stars
36 (31%)
3 stars
15 (13%)
2 stars
3 (2%)
1 star
0 (0%)
Displaying 1 - 4 of 4 reviews
Profile Image for Jay French.
2,163 reviews91 followers
February 13, 2017
I probably wasn’t reading this in the manner the authors intended, but I found it quite interesting and educational – it fit my purpose. Computer security is not my line, but I feel it is imperative for those managing information technology at companies to understand the current battleground of computer security, and to get a taste for the tactics used by the elusive hacker as well as the possible avenues of investigation and response. I would say this book provided an excellent intermediate level of information. Any more detailed and you are talking about an encyclopedia’s worth of text that changes on a very regular basis. Any less detail and you have something that can only be used as a generic roadmap, aimed at managers but not practitioners. Here, my manager mind got an excellent description of how many kinds of attacks work, how and where evidence can be found through investigation, and how to remediate the issue. In addition, my technical background, mostly back a generation or two in the technology, got an update on areas of interest, including the current state of Windows technology, like how file systems work, and on tools that help in an investigation, describing some of the differences between paid and free tools. One of the issues in a book like this is that it is written at a point in time, and things change. Vendors update products, hackers try new methods. The authors took an “intermediate” approach by describing a variety of tools and hacker methods, but providing pointers to websites for the reader to get up-to-date information. So although this version of the book was 3 years old, it still reads as if it is current and retains value. Worthwhile for an update on the state of affairs, and likely worthwhile for a practitioner beginning in the battle.
Profile Image for Takedown.
137 reviews9 followers
December 24, 2016
Written by Mandiant founders and experts - this book covers a full lifecycle of Incident Response including various non-technical considerations.
Easy and concise to read, filled with tips and practical examples, this is the best fundamental IR material from the people who basically invent the field. As a bonus you get a unique glimpse into how Mandiant operate. What more do you need?
This book would be useful for technical IR personnel in the trenches as well as management folks, especially people creating and leading CSIRT teams.
Look no further if you want to know what Incident Response is all about!
Displaying 1 - 4 of 4 reviews

Can't find what you're looking for?

Get help and learn more about the design.