
Explore advanced computer forensics concepts and practices, including ram acquisitions, live forensics, Windows Registry analysis, usb evidence, network connections, signature search, wifi activity, court testimony, and nontraditional devices.
Explore memory forensics by understanding RAM, its volatility, and what unsaved documents, chat messages, clipboard contents, open network connections, and malware reveal about a running system.
perform a ram capture using the fctc imager on a live machine, saving a memory dump and page file, then locate and prepare the resulting dot MGM and image files.
Analyze memory dumps with Volatility Workbench to identify running processes, modules, and system information, and learn to extract evidence from RAM for forensic reporting.
The Windows registry holds a wealth of system information, including default and user-defined settings, software inventory, USB usage, and recently visited websites for forensic analysis.
Acquiring the registry from a live machine demonstrates obtaining all registry files and password-protected data from a live system. Exporting these files to a host enables subsequent analysis.
Extract registry information from an image file using FTK Imager, exporting the SAM, Security, and System hives along with related user data for forensic analysis.
Demonstrates using the Reg Ripper registry analysis tool to extract, analyze registry hives like security and software, run modules, and generate log and results reports for forensic examination.
Explore how to extract a Windows user profile from NTUSER.DAT, accessing modules such as the nation module, recent documents, run history, typed URLs, media cache, and zip usage.
Learn USB forensics by analyzing the host machine and the USB drive, using Windows registry techniques to determine when USB devices connected and what files were added or removed.
Explore how Wi-Fi networking works and how forensic analysts extract which networks a device connected to, when, and where, from the Windows registry's network list profiles.
Identify network connections and interfaces by inspecting the system registry, extracting IP addresses, DHCP, and domain data with RegRipper for forensic correlation.
Compare live forensics with dead box forensics to capture RAM and processes. Document precautions, acknowledge non-reproducible results, and follow the order of volatility to prioritize registry and network state.
Practice live forensic acquisition by creating a raw disk image from a live drive with a write blocker, capturing memory and registry data, and ensuring sufficient space.
Discover how search signatures differ by search engine and how url query parameters reveal the terms searched, enabling detection of post hoc manipulation in forensic analysis.
Examine internet of things devices—smart watches, smart TVs, and smart speakers—and learn forensic acquisition strategies, including device contents, connections, and cloud-based evidence via client apps.
Analyze video game systems for forensics by examining encrypted drives, proprietary files, and cloud data across PlayStation, Xbox, and Nintendo Switch, using standard PC-like procedures.
Explore the differences between IP cameras and CCTV, including cloud vs local storage, and learn forensic seizure practices to preserve video evidence.
Study drone forensics to identify flight paths, recover user data and multimedia from drones, and secure logs, emails, and maps for prosecuting criminal drone activity.
Learn how forensic examiners testify in court, defend acquisition methods and tool choices, and ensure reproducible conclusions from their forensics reports.
Review RAM acquisition analysis, Windows registry forensics, live acquisitions, signature searches, and nontraditional devices, plus court testimony. Explore certifications, practice, and career paths in computer forensics.
This course is designed for people with a working knowledge of computer forensics but looking to go deeper into specific skill and techniques of the the field. We cover techniques and examine devices that are more volatile or more difficult to access than a standard PC acquisition. This is the third course following my pervious course Computer Forensics Fundamentals and Intermediated Computer Forensics. While those course are recommended it is not required to take this course as they are independent in regard to topics taught.
Advanced Computer Forensics will provide:
Ram Acquisition and Analysis
Windows registry forensics
Hives and NTUSER.dat
USB and network connections
Live forensic acquisitions
Search Signatures
Non-traditional devices (Internet of Things), games systems, drones and camera systems
Testifying in a court of law
The course will consist of presentations to explain the concepts of computer forensics as well as demonstrations of proper software and collections of digital evidence, using primary open source or free software so that students can replicate the demonstrations on their own. Quizzes will reenforce the concepts.
This course is designed for anyone with an interest computer forensics to get a deeper taste of the real world of digital forensics examination.
As an advanced course it will consist of presentations, hands on lessons and quizs.