Learning Python for Forensics
Learn the art of designing, developing, and deploying innovative forensic solutions through Python


• This practical guide will help you solve forensic dilemmas through the development of Python scripts

• Analyze Python scripts to extract metadata and investigate forensic artifacts

• Master the skills of parsing complex data structures by taking advantage of Python libraries

If you are a forensics student, hobbyist, or professional that is seeking to increase your understanding in forensics through the use of a programming language, then this book is for you.

You are not required to have previous experience in programming to learn and master the content within this book. This material, created by forensic professionals, was written with a unique perspective and understanding of examiners who wish to learn programming


• Discover how to perform Python script development

• Update yourself by learning the best practices in forensic programming

• Build scripts through an iterative design

• Explore the rapid development of specialized scripts

• Understand how to leverage forensic libraries developed by the community

• Design flexibly to accommodate present and future hurdles

• Conduct effective and efficient investigations through programmatic pre-analysis

• Discover how to transform raw data into customized reports and visualizations

This book will illustrate how and why you should learn Python to strengthen your analysis skills and efficiency as you creatively solve real-world problems through instruction-based tutorials. The tutorials use an interactive design, giving you experience of the development process so you gain a better understanding of what it means to be a forensic developer.

Each chapter walks you through a forensic artifact and one or more methods to analyze the evidence. It also provides reasons why one method may be advantageous over another. We cover common digital forensics and incident response scenarios, with scripts that can be used to tackle case work in the field. Using built-in and community-sourced libraries, you will improve your problem solving skills with the addition of the Python scripting language. In addition, we provide resources for further exploration of each script so you can understand what further purposes Python can serve. With this knowledge, you can rapidly develop and deploy solutions to identify critical information and fine-tune your skill set as an examiner.

The book begins by instructing you on the basics of Python, followed by chapters that include scripts targeted for forensic casework. Each script is described step by step at an introductory level, providing gradual growth to demonstrate the available functionalities of Python.

1123738170
Learning Python for Forensics
Learn the art of designing, developing, and deploying innovative forensic solutions through Python


• This practical guide will help you solve forensic dilemmas through the development of Python scripts

• Analyze Python scripts to extract metadata and investigate forensic artifacts

• Master the skills of parsing complex data structures by taking advantage of Python libraries

If you are a forensics student, hobbyist, or professional that is seeking to increase your understanding in forensics through the use of a programming language, then this book is for you.

You are not required to have previous experience in programming to learn and master the content within this book. This material, created by forensic professionals, was written with a unique perspective and understanding of examiners who wish to learn programming


• Discover how to perform Python script development

• Update yourself by learning the best practices in forensic programming

• Build scripts through an iterative design

• Explore the rapid development of specialized scripts

• Understand how to leverage forensic libraries developed by the community

• Design flexibly to accommodate present and future hurdles

• Conduct effective and efficient investigations through programmatic pre-analysis

• Discover how to transform raw data into customized reports and visualizations

This book will illustrate how and why you should learn Python to strengthen your analysis skills and efficiency as you creatively solve real-world problems through instruction-based tutorials. The tutorials use an interactive design, giving you experience of the development process so you gain a better understanding of what it means to be a forensic developer.

Each chapter walks you through a forensic artifact and one or more methods to analyze the evidence. It also provides reasons why one method may be advantageous over another. We cover common digital forensics and incident response scenarios, with scripts that can be used to tackle case work in the field. Using built-in and community-sourced libraries, you will improve your problem solving skills with the addition of the Python scripting language. In addition, we provide resources for further exploration of each script so you can understand what further purposes Python can serve. With this knowledge, you can rapidly develop and deploy solutions to identify critical information and fine-tune your skill set as an examiner.

The book begins by instructing you on the basics of Python, followed by chapters that include scripts targeted for forensic casework. Each script is described step by step at an introductory level, providing gradual growth to demonstrate the available functionalities of Python.

51.99 In Stock
Learning Python for Forensics

Learning Python for Forensics

Learning Python for Forensics

Learning Python for Forensics

eBook

$51.99 

Available on Compatible NOOK devices, the free NOOK App and in My Digital Library.
WANT A NOOK?  Explore Now

Related collections and offers


Overview

Learn the art of designing, developing, and deploying innovative forensic solutions through Python


• This practical guide will help you solve forensic dilemmas through the development of Python scripts

• Analyze Python scripts to extract metadata and investigate forensic artifacts

• Master the skills of parsing complex data structures by taking advantage of Python libraries

If you are a forensics student, hobbyist, or professional that is seeking to increase your understanding in forensics through the use of a programming language, then this book is for you.

You are not required to have previous experience in programming to learn and master the content within this book. This material, created by forensic professionals, was written with a unique perspective and understanding of examiners who wish to learn programming


• Discover how to perform Python script development

• Update yourself by learning the best practices in forensic programming

• Build scripts through an iterative design

• Explore the rapid development of specialized scripts

• Understand how to leverage forensic libraries developed by the community

• Design flexibly to accommodate present and future hurdles

• Conduct effective and efficient investigations through programmatic pre-analysis

• Discover how to transform raw data into customized reports and visualizations

This book will illustrate how and why you should learn Python to strengthen your analysis skills and efficiency as you creatively solve real-world problems through instruction-based tutorials. The tutorials use an interactive design, giving you experience of the development process so you gain a better understanding of what it means to be a forensic developer.

Each chapter walks you through a forensic artifact and one or more methods to analyze the evidence. It also provides reasons why one method may be advantageous over another. We cover common digital forensics and incident response scenarios, with scripts that can be used to tackle case work in the field. Using built-in and community-sourced libraries, you will improve your problem solving skills with the addition of the Python scripting language. In addition, we provide resources for further exploration of each script so you can understand what further purposes Python can serve. With this knowledge, you can rapidly develop and deploy solutions to identify critical information and fine-tune your skill set as an examiner.

The book begins by instructing you on the basics of Python, followed by chapters that include scripts targeted for forensic casework. Each script is described step by step at an introductory level, providing gradual growth to demonstrate the available functionalities of Python.


Product Details

ISBN-13: 9781783285242
Publisher: Packt Publishing
Publication date: 05/31/2016
Sold by: Barnes & Noble
Format: eBook
Pages: 488
File size: 9 MB

About the Author

Preston Miller is a consultant at an internationally recognized firm that specializes in cyber investigations. Preston holds an undergraduate degree from Vassar College and a master's degree in digital forensics from Marshall University, where he was the recipient of the J. Edgar Hoover Scientific Scholarship for academic excellence. While studying in a graduate school, Preston conducted classes on Python and Open Source Forensics. Preston has previously published his research on Bitcoin through Syngress.
Preston is experienced in conducting traditional Digital Forensic investigations, but specializes in Physical Forensics. Physical Forensics is a subset of Digital Forensics, which involves black box scenarios where data must be acquired from a device by non-traditional means. In his free time, Preston contributes to multiple Python-based open source projects.

Chapin Bryce is a professional in the digital forensics community. After studying computers and digital forensics at Champlain College, Chapin joined a firm leading the field of digital forensics and investigations. In his downtime, Chapin enjoys working on Python scripts, writing, and skiing (weather permitting). As a member of multiple ongoing research and development projects, Chapin has authored several articles in professional and academic publications.

Table of Contents

  1. Now For Something Completely Different
  2. Python Fundamentals
  3. Parsing Text Files
  4. Working with Serialized Data Structures
  5. Databases in Python
  6. Extracting Artifacts from Binary Files
  7. Fuzzy Hashing
  8. The Media Age
  9. Uncovering Time
  10. Did Someone Say Keylogger?
  11. Parsing Outlook PST Containers
  12. Recovering Transient Database Records
  13. Coming Full Circle
From the B&N Reads Blog

Customer Reviews