Security Focus ran a monthly serial a while back called "No Stone Unturned" about the forays of a Sys Admin into the realm of forensics. Although fictional, there is some very useful info in the story (it's good reading to boot). In particular, parts 5 and 6 have a good overview of the kinds of tools to include on a forensics CD. Part 6 can be found here: http://online.securityfocus.com/infocus/1618 <http://online.securityfocus.com/infocus/1618>
This archive was generated by hypermail 2b30 : Wed Oct 09 2002 - 16:05:08 PDT