Skip to main content
  • Textbook
  • © 2020

Fundamentals of Digital Forensics

Theory, Methods, and Real-Life Applications

Authors:

  • Enhanced new edition featuring expanded content on corporate forensics (incident response and management), ethical issues, SQLite databases, forensic triage, and memory analysis
  • Presents a strong theoretical discussion on forensic concepts and important considerations during a forensic examination
  • Contains a detailed section that describes and discusses important artifacts
  • Provides review questions and practice tasks at the end of most chapters, and supporting video lectures on YouTube

Buy it now

Buying options

eBook USD 44.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book USD 59.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Other ways to access

This is a preview of subscription content, log in via an institution to check for access.

Table of contents (21 chapters)

  1. Front Matter

    Pages i-xiii
  2. Part I

    1. Front Matter

      Pages 1-1
    2. What Is Digital Forensics?

      • Joakim Kävrestad
      Pages 3-7
    3. Ethics and Integrity

      • Joakim Kävrestad
      Pages 9-16
    4. Computer Theory

      • Joakim Kävrestad
      Pages 17-29
    5. Notable Artifacts

      • Joakim Kävrestad
      Pages 31-45
    6. Decryption and Password Enforcing

      • Joakim Kävrestad
      Pages 47-55
  3. Part II

    1. Front Matter

      Pages 57-57
    2. Incident Response

      • Joakim Kävrestad
      Pages 63-68
    3. Collecting Evidence

      • Joakim Kävrestad
      Pages 69-78
    4. Triage

      • Joakim Kävrestad
      Pages 79-83
    5. Analyzing Data and Writing Reports

      • Joakim Kävrestad
      Pages 85-98
  4. Part III

    1. Front Matter

      Pages 99-99
    2. Collecting Data

      • Joakim Kävrestad
      Pages 101-113
    3. Indexing and Searching

      • Joakim Kävrestad
      Pages 115-121
    4. Cracking

      • Joakim Kävrestad
      Pages 123-133
    5. Finding Artifacts

      • Joakim Kävrestad
      Pages 135-153
    6. Some Common Questions and Tasks

      • Joakim Kävrestad
      Pages 155-167
    7. FTK Specifics

      • Joakim Kävrestad
      Pages 169-187

About this book

This practical and accessible textbook/reference describes the theory and methodology of digital forensic examinations, presenting examples developed in collaboration with police authorities to ensure relevance to real-world practice. The coverage includes discussions on forensic artifacts and constraints, as well as forensic tools used for law enforcement and in the corporate sector. Emphasis is placed on reinforcing sound forensic thinking, and gaining experience in common tasks through hands-on exercises.

This enhanced second edition has been expanded with new material on incident response tasks and computer memory analysis.

Topics and features:

  • Outlines what computer forensics is, and what it can do, as well as what its limitations are
  • Discusses both the theoretical foundations and the fundamentals of forensic methodology
  • Reviews broad principles that are applicable worldwide
  • Explains how to findand interpret several important artifacts
  • Describes free and open source software tools, along with the AccessData Forensic Toolkit
  • Features exercises and review questions throughout, with solutions provided in the appendices
  • Includes numerous practical examples, and provides supporting video lectures online

This easy-to-follow primer is an essential resource for students of computer forensics, and will also serve as a valuable reference for practitioners seeking instruction on performing forensic examinations.

Joakim Kävrestad is a lecturer and researcher at the University of Skövde, Sweden, and an AccessData Certified Examiner. He also serves as a forensic consultant, with several years of experience as a forensic expert with the Swedish police.


Authors and Affiliations

  • School of Informatics, University of Skövde, Skövde, Sweden

    Joakim Kävrestad

About the author

Joakim Kävrestad is a lecturer and researcher at the University of Skövde, Sweden, and an AccessData Certified Examiner. He also serves as a forensic consultant, with several years of experience as a forensic expert with the Swedish police.

Bibliographic Information

  • Book Title: Fundamentals of Digital Forensics

  • Book Subtitle: Theory, Methods, and Real-Life Applications

  • Authors: Joakim Kävrestad

  • DOI: https://doi.org/10.1007/978-3-030-38954-3

  • Publisher: Springer Cham

  • eBook Packages: Computer Science, Computer Science (R0)

  • Copyright Information: Springer Nature Switzerland AG 2020

  • Softcover ISBN: 978-3-030-38953-6Published: 20 May 2020

  • eBook ISBN: 978-3-030-38954-3Published: 19 May 2020

  • Edition Number: 2

  • Number of Pages: XIII, 268

  • Number of Illustrations: 116 b/w illustrations, 27 illustrations in colour

  • Topics: Systems and Data Security, Image Processing and Computer Vision, Crime Control and Security

Buy it now

Buying options

eBook USD 44.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book USD 59.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Other ways to access