Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 35 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Incident Responsearrow What are your recommendations for Incident Response books?
EH-Net
May 19, 2013, 11:45:10 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: What are your recommendations for Incident Response books?  (Read 4949 times)
0 Members and 1 Guest are viewing this topic.
unsupported
Sr. Member
****
Offline Offline

Posts: 318


Unofficial Newbie Moderator


View Profile
« on: February 11, 2009, 11:35:15 AM »

I was planning on going for GCIH, but our companies budget hadn't gone through, so I moved to my backup plan for CEH.  I still want to get a grasp on IR doing self-study with hopes of getting my company to send me to GCIH training.  I wanted to start reading Counter Hack Reloaded, but wanted to know what other recommendations everyone has for IR.

Thank you!
Logged

-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #1 on: February 11, 2009, 12:22:37 PM »

Hey Unsupported!

I would start by looking at the free resources here:


http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,3488.msg16165/#msg16165


And Security Focus has some good (a little old) whitepapers too:

http://www.securityfocus.com/incidents

As for a book, other than GCIH books i only own:

Incident Response: A Strategic Guide to Handling System and Network Security Breaches

Which is a classic imo

Good luck!
Logged

jason
Hero Member
*****
Offline Offline

Posts: 1012



View Profile WWW
« Reply #2 on: February 11, 2009, 03:29:28 PM »

Also:

http://www.amazon.com/Incident-Response-Computer-Forensics-Toolkit/dp/0764526367/ref=pd_sim_b_2

http://www.amazon.com/Incident-Response-Computer-Forensics-Second/dp/007222696X/ref=pd_sim_b_7

http://www.amazon.com/Principles-Incident-Response-Disaster-Recovery/dp/141883663X/ref=pd_sim_b_20

http://www.amazon.com/Incident-Response-Kenneth-van-Wyk/dp/0596001304/ref=pd_sim_b_27

Some of these are getting a bit long in the tooth now...
Logged
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #3 on: February 11, 2009, 07:38:34 PM »

Also I hear good things about


Incident Response and Computer Forensics, Second Edition
By Chris Prosise, Kevin Mandia, Matt Pepe

and its on EH's Chris Gates book wishlist =)
Logged

Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #4 on: February 13, 2009, 04:35:02 AM »

Hello unsupported!

The links by Jhaddix and Jason pretty much covers it all and I think would be sufficient to help you get a good grasp of the subject.
In case you want  some reviews of the books you should go for I suggest reading this article by Tony Bradley. Perhaps these would be enough to give you a nice start.
Logged
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #5 on: February 14, 2009, 02:03:07 PM »

NIST has lots of great papers on this (and other) subjects. NIST 800-61 is a great resource. I especially found the example scenarios helpful since it will allow you to go through some example situations before (hopefully) one actually happens.

csrc.nist.gov/publications/nistpubs/800-61/sp800-61.pdf
Logged

twitter.com/timmedin | http://blog.securitywhole.com
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.074 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.