Perl Scripting for Windows Security: Live Response, Forensic Analysis, and Monitoring
Carvey, Harlan
Couldn't load pickup availability
Table of contents
- Cover
- Contentsxi
- Prefacexiii
- Author Acknowledgementsxxiii
- Part I: Perl Scripting and Live Response1
- Built-in Functions2
- Win32.pl2
- Pclip.pl3
- Running Processes4
- Netstat1.pl5
- Netstat2.pl6
- Netstat3.pl7
- Accessing the API8
- Getsys.pl10
- WMI14
- Fw.pl15
- Nic.pl20
- Ndis.pl24
- Di.pl28
- Ldi.pl32
- Accessing the Registry36
- Bho.pl36
- Uassist.pl38
- ProScripts44
- Acquire1.pl44
- Final Touches47
- Part II: Perl Scripting and Computer Forensic Analysis49
- Log Files50
- Parsing Binary Files51
- Lslnk.pl52
- Registry58
- SAMParse.pl60
- SECParse.pl68
- Recentdocs.pl71
- UAssist.pl75
- Event Logs80
- Evt2xls.pl80
- Parsing RAM Dumps87
- Lsproc.pl88
- Lspi.pl94
- ProScripts105
- Uassist.pl106
- SysRestore.pl110
- Prefetch.pl117
- Parsing Other Data122
- Cc-sort.pl128
- Final Touches128
- Part III: Monitoring Windows Applications with Perl131
- In This Toolbox132
- Core Application Processes132
- Monitoring System Key Performance Indicators133
- Monitoring System CPU Utilization133
- Monitoring System Memory Utilization139
- Monitoring System Network Utilization141
- Monitoring a Core Application Process145
- Monitoring Process Availability a Specific Process145
- Monitoring CPU Utilization for a Specific Process149
- Monitoring Memory Utilization for a Specific Process152
- Setting and Using Thresholds154
- Loading an XML Configuration File155
- Evaluating Thresholds158
- Taking Action163
- Putting it all Together168
- Core Application Dependencies173
- Monitoring Remote System Availability174
- Monitoring Available Disk Space175
- Monitoring Remote Disk Availability177
- Monitoring Remote Databases179
- Monitoring Other Dependencies180
- Web Services181
- Monitoring Web Service Availability181
- Monitoring Web Service Functionality183
- Building a Monitoring System185
- Summary192
- Index193
- Vendor Elsevier S & T
- SKU 9781597491730
- ISBN-13 9780080555638
- Author Carvey, Harlan
- Category Mathematics
- Subject Applied
Do you have questions about this book?
I decided to write this book for a couple of reasons. One was that I’ve now written a couple of books that have to do with incident response and forensic analysis on Windows systems, and I used a lot of Perl in both books. Okay…I’ll come clean…I used nothing but Perl in both books! What I’ve seen as a result of this is that many readers want to use the tools, but don’t know how…they simply aren’t familiar with Perl, with interpreted (or scripting) languages in general, and may not be entirely comfortable with running tools at the command line. This book is intended for anyone who has an interest in useful Perl scripting, in particular on the Windows platform, for the purpose of incident response, and forensic analysis, and application monitoring. While a thorough grounding in scripting languages (or in Perl specifically) is not required, it helpful in fully and more completely understanding the material and code presented in this book. This book contains information that is useful to consultants who perform incident response and computer forensics, specifically as those activities pertain to MS Windows systems (Windows 2000, XP, 2003, and some Vista). My hope is that not only will consultants (such as myself) find this material valuable, but so will system administrators, law enforcement officers, and students in undergraduate and graduate programs focusing on computer forensics.
Code can be found at: http://www.elsevierdirect.com/companion.jsp?ISBN=9781597491730
*Perl Scripting for Live Response
Using Perl, there’s a great deal of information you can retrieve from systems, locally or remotely, as part of troubleshooting or investigating an issue. Perl scripts can be run from a central management point, reaching out to remote systems in order to collect information, or they can be "compiled" into standalone executables using PAR, PerlApp, or Perl2Exe so that they can be run on systems that do not have ActiveState’s Perl distribution (or any other Perl distribution) installed.
*Perl Scripting for Computer Forensic Analysis
Perl is an extremely useful and powerful tool for performing computer forensic analysis. While there are applications available that let an examiner access acquired images and perform some modicum of visualization, there are relatively few tools that meet the specific needs of a specific examiner working on a specific case. This is where the use of Perl really shines through and becomes apparent.
*Perl Scripting for Application Monitoring
Working with enterprise-level Windows applications requires a great deal of analysis and constant monitoring. Automating the monitoring portion of this effort can save a great deal of time, reduce system downtimes, and improve the reliability of your overall application. By utilizing Perl scripts and integrating them with the application technology, you can easily build a simple monitoring framework that can alert you to current or future application issues.
Instant delivery by email
Your access email arrives within minutes of checkout, with a sign-in link for each book — no shipping, no waiting.
Read on any device
Books open in VitalSource Bookshelf on your phone, tablet, or computer, online or offline. Your library is always available at aafaq.vitalsource.com — just log in with the email you used at checkout.
Lost the email?
Resend it to yourself in seconds from My eBook orders, or email cs@aafaqeducation.com and we'll help.