{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,29]],"date-time":"2025-06-29T11:40:02Z","timestamp":1751197202021,"version":"3.41.0"},"publisher-location":"Cham","reference-count":24,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319736969"},{"type":"electronic","value":"9783319736976"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-73697-6_2","type":"book-chapter","created":{"date-parts":[[2018,1,5]],"date-time":"2018-01-05T02:53:43Z","timestamp":1515120823000},"page":"18-32","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Real-Time Forensics Through Endpoint Visibility"],"prefix":"10.1007","author":[{"given":"Peter","family":"Kieseberg","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sebastian","family":"Neuner","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sebastian","family":"Schrittwieser","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Martin","family":"Schmiedecker","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Edgar","family":"Weippl","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,1,6]]},"reference":[{"key":"2_CR1","doi-asserted-by":"crossref","unstructured":"Alsagoff, S.N.: Malware self protection mechanism. In: 2008 International Symposium on Information Technology, vol. 3, pp. 1\u20138 (2008)","DOI":"10.1109\/ITSIM.2008.4631981"},{"key":"2_CR2","unstructured":"Auchard, E.: Major security breaches found in Google and Yahoo email services. Accessed 13 Sept 2016"},{"key":"2_CR3","volume-title":"File System Forensic Analysis","author":"B Carrier","year":"2005","unstructured":"Carrier, B.: File System Forensic Analysis. Addison-Wesley Professional, Boston (2005)"},{"key":"2_CR4","volume-title":"Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet","author":"E Casey","year":"2011","unstructured":"Casey, E.: Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet. Academic Press, Orlando (2011)"},{"key":"2_CR5","doi-asserted-by":"crossref","first-page":"S101","DOI":"10.1016\/j.diin.2011.05.012","volume":"8","author":"MI Cohen","year":"2011","unstructured":"Cohen, M.I., Bilby, D., Caronni, G.: Distributed forensics and incident response in the enterprise. Digit. Invest. 8, S101\u2013S110 (2011)","journal-title":"Digit. Invest."},{"key":"2_CR6","doi-asserted-by":"crossref","first-page":"S57","DOI":"10.1016\/j.diin.2009.06.010","volume":"6","author":"M Cohen","year":"2009","unstructured":"Cohen, M., Garfinkel, S., Schatz, B.: Extending the advanced forensic format to accommodate multiple data sources, logical evidence, arbitrary information and forensic workflow. Digit. Invest. 6, S57\u2013S68 (2009)","journal-title":"Digit. Invest."},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Comparetti, P.M., Salvaneschi, G., Kirda, E., Kolbitsch, C., Kruegel, C., Zanero, S.: Identifying dormant functionality in malware programs. In: IEEE Symposium on Security and Privacy. IEEE (2010)","DOI":"10.1109\/SP.2010.12"},{"key":"2_CR8","doi-asserted-by":"crossref","first-page":"S90","DOI":"10.1016\/j.diin.2015.01.016","volume":"12","author":"F Cruz","year":"2015","unstructured":"Cruz, F., Moser, A., Cohen, M.: A scalable file based data store for forensic analysis. Digit. Invest. 12, S90\u2013S101 (2015)","journal-title":"Digit. Invest."},{"issue":"6","key":"2_CR9","first-page":"8","volume":"32","author":"D Dittrich","year":"2007","unstructured":"Dittrich, D., Dietrich, S.: Command and control structures in malware. Usenix Mag. 32(6), 8\u201317 (2007)","journal-title":"Usenix Mag."},{"key":"2_CR10","doi-asserted-by":"crossref","first-page":"S64","DOI":"10.1016\/j.diin.2010.05.009","volume":"7","author":"SL Garfinkel","year":"2010","unstructured":"Garfinkel, S.L.: Digital forensics research: the next 10 years. Digit. Invest. 7, S64\u2013S73 (2010)","journal-title":"Digit. Invest."},{"key":"2_CR11","doi-asserted-by":"crossref","unstructured":"Guo, H., Jin, B., Shang, T.: Forensic investigations in cloud environments. In: 2012 International Conference on Computer Science and Information Processing (CSIP), pp. 248\u2013251. IEEE (2012)","DOI":"10.1109\/CSIP.2012.6308841"},{"key":"2_CR12","unstructured":"Facebook Inc. osquery performant endpoint visibility. Accessed 13 Sept 2016"},{"key":"2_CR13","first-page":"800","volume":"10","author":"K Kent","year":"2006","unstructured":"Kent, K., Chevalier, S., Grance, T., Dang, H.: Guide to integrating forensic techniques into incident response. NIST Spec. Publ. 10, 800\u2013886 (2006)","journal-title":"NIST Spec. Publ."},{"key":"2_CR14","unstructured":"Kolbitsch, C., Comparetti, P.M., Kruegel, C., Kirda, E., Zhou, X.-Y., Wang, X.: Effective and efficient malware detection at the end host. In: USENIX Security Symposium, pp. 351\u2013366 (2009)"},{"key":"2_CR15","unstructured":"Mosendz, P.: Lets calculate how much money Facebook just lost during todays outage. Accessed 13 Sept 2016"},{"issue":"2","key":"2_CR16","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1016\/j.diin.2013.03.003","volume":"10","author":"A Moser","year":"2013","unstructured":"Moser, A., Cohen, M.I.: Hunting in the enterprise: forensic triage and incident response. Digit. Invest. 10(2), 89\u201398 (2013)","journal-title":"Digit. Invest."},{"key":"2_CR17","unstructured":"Mozilla. Mig: Mozilla investigator. Accessed 13 Sept 2016"},{"issue":"15","key":"2_CR18","doi-asserted-by":"crossref","first-page":"2876","DOI":"10.1002\/sec.1418","volume":"9","author":"S Neuner","year":"2016","unstructured":"Neuner, S., Schmiedecker, M., Weippl, E.: Effectiveness of file-based deduplication in digital forensics. Secur. Commun. Netw. 9(15), 2876\u20132885 (2016). Wiley Online Library","journal-title":"Secur. Commun. Netw."},{"key":"2_CR19","unstructured":"National Institute of Standards, Technology (NIST), and United States of America. Forensic examination of digital evidence: a guide for law enforcement (2004)"},{"key":"2_CR20","unstructured":"Pollitt, M.: Computer forensics: an approach to evidence in cyberspace. In: Proceedings of the National Information Systems Security Conference, vol. 2, pp. 487\u2013491 (1995)"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"Pollitt, M.M.: An ad hoc review of digital forensic models. In: Second International Workshop on Systematic Approaches to Digital Forensic Engineering, SADFE 2007, pp. 43\u201354. IEEE (2007)","DOI":"10.1109\/SADFE.2007.3"},{"key":"2_CR22","unstructured":"Ty, S.: osquery: cross-platform, lightweight, and performant host visibility. In: 7th Annual Open Source Digital Forensics Conference (OSDFCon) (2016)"},{"key":"2_CR23","unstructured":"Wahnon, M.: Awesome-incident-response: all-one-tools. Accessed 13 Sept 2016"},{"key":"2_CR24","doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D., Egele, M., Kruegel, C., Kirda, E.: Panorama: capturing system-wide information flow for malware detection and analysis. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 116\u2013127. ACM (2007)","DOI":"10.1145\/1315245.1315261"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Digital Forensics and Cyber Crime"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-73697-6_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,29]],"date-time":"2025-06-29T10:59:54Z","timestamp":1751194794000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-73697-6_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319736969","9783319736976"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-73697-6_2","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2018]]}}}