Useful Links for Security Incident Response
CERT/CC Incident Response FAQ
(URL://www.cert.org/csirts/csirt_faq.html)
Collecting Electronic Evidence After a System
Compromise
(URL://www.auscert.org.au/render.html?it=2247&cid=1920)
Steps for Recovering from a UNIX or NT System
Compromise
(URL://www.auscert.org.au/render.html?it=1974&cid=1920)
SANS Reading Room – Incident Handling
(URL://www.sans.org/reading_room/whitepapers/incident/)
The
Hong Kong Police Force Commercial Crime Bureau
- Technology Crime Division
|