
Examine removable and optical storage media, from magnetic tape and floppy disks to CDs, DVDs, Blu-ray, and cloud storage, with laser types, capacities, and data forensics considerations.
Explore flash storage media, NAND and NOR flash, and EEPROM, and examine USB interfaces and their read-write speeds from 1.1 to 4.0.
Explore flash memory cards, including SD and micro SD formats, NAND memory, and how USB card readers enable data access and recovery.
Explore hard disk drives as fixed storage media, from mechanical drives with moving parts to sata and ide interfaces, and their forensic relevance, including hybrid drives.
Explore how solid state drives use non-volatile NAND flash memory, a controller, and SATA interfaces to deliver fast, durable storage, with wear leveling, error correction, garbage collection, and trim.
Create a bootable forensic media toolkit using Kane OS on USB, ensuring an isolated, write-protected environment for forensic imaging and analysis with Rufus and secure boot considerations.
Explore the boot process from power-on self-test to loading the operating system, covering BIOS and uEFI, boot sequences, MBR vs GPT, and creating forensic boot media.
Learn to assemble an on site digital evidence response kit, including documentary, paperwork, storage containers, and a range of hardware and software tools.
Explore the critical differences between live and postmortem acquisitions, preserving volatile random access memory data and paging files while imaging and safeguarding against data loss on powered devices.
Acquire evidence and create forensic disk images with FTK Imager, using physical and logical drives, verify integrity with checksums and hashes, and manage case metadata and image formats.
Explore how Linux names disks and partitions for forensic analysis, and apply bit stream copies and data hashes to preserve evidence and ensure reproducibility.
Identify storage devices with the fdisk command and perform forensic acquisition using dd, while applying hardware or software write blockers to protect evidence integrity.
Preserve evidence integrity by hashing data before and after acquisition with md5sum and sha1sum, and verify image fidelity with dc3dd, illustrating the avalanche effect.
Explore DC3D for forensic imaging, including on-the-fly hashing with MD5, hash verification, progress meters, error logging, and secure output management.
Master forensic imaging with DC 3D, split large images into portable parts, and verify integrity using sha1 hashing, logs, and recombining split files to ensure exact, tamper-free evidence.
Master GUI-based forensic imaging with Guymager to acquire and clone drives, using expert witness metadata, case management details, and hash verification options (md5, sha1, sha256) for tamper-evident results.
Capture Windows volatile memory with FTK Imager to preserve RAM for forensic analysis, running from an external drive and documenting hash values to support chain of custody.
Explore memory forensics with the Volatility framework, extracting data from RAM and the swap file to reveal credentials and active or hidden processes, and learn setup on Linux and plugins.
Explore hands-on memory forensics using Volatility plugins to analyze a Windows XP memory dump, identify the OS profile, and retrieve running processes and artifacts.
Explore volatility ps3, ps scan, and ps view to map process relationships, reveal hidden or terminated processes, and compare visibility across scans for malware detection.
Explore volatility-driven network and dll analysis to uncover memory-resident connections, open sockets, loaded DLLs, and user SIDs, revealing potential malware and backdoor activity.
Explore autopsy, a graphical interface over the Sleuth Kit, and learn to analyze disk images, recover deleted data, hash files, and generate forensic reports.
Autopsy guides investigators through image analysis, detailing image details, file analysis, MD5 hashes, and metadata, while identifying deleted files, exploring directories, and annotating findings.
Autopsy guides analysts through the file type tab to sort allocated, deleted, and hidden files, producing an HTML output that highlights extensions, images, and other artifacts for forensic investigation.
Unlock the secrets of computer forensics and digital investigations with this advanced, hands-on course designed to empower you with the skills needed to excel in the Digital Forensics and Incident Response (DFIR) field. Whether you're aiming to master on-scene investigations, digital evidence acquisition, memory analysis, or dive deep into forensic tools like FTK Imager and Autopsy, this comprehensive course will equip you with the real-world skills and methodologies used by top forensic professionals.
Why Enroll in This Course?
In today’s digital world, understanding and leveraging digital forensics is a game-changer in solving cybercrimes, securing IT environments, and supporting law enforcement. This course goes beyond the basics, blending theoretical knowledge with practical application, and focuses on real-life scenarios and hands-on exercises that mimic actual crime scenes. With carefully curated lectures, expert-guided modules, and detailed tool demos, you’ll gain the confidence to tackle complex investigations and enhance your forensic expertise.
What You'll Learn:
Foundational Knowledge of Storage Media: Start with the essentials of data storage—from optical media to solid-state drives—and understand the nuances of different media that hold valuable digital evidence.
Bootable Forensic Media and Boot Process Analysis: Learn to create bootable forensic media, essential for live investigations, and dive into the boot process, unraveling key stages where critical digital artifacts reside.
Field-Ready Forensic Skills: Explore the essentials for on-scene digital investigations, including distinguishing between live and post-mortem acquisition methods and the must-have tools for a successful investigation.
Evidence Acquisition Mastery: Uncover the best practices for disk and memory imaging with industry-leading tools like FTK Imager, Guymager, and DC3DD, and gain expertise in evidence integrity and write-blocking techniques to preserve data authenticity.
Memory Analysis with Volatility: Delve into memory analysis using the powerful Volatility Framework—understand plugin capabilities, process analysis, and network and DLL examination for a comprehensive memory investigation.
Autopsy Tool for Digital Evidence Examination: From downloading sample images to a thorough walkthrough of Autopsy, master this all-in-one forensics platform to gather, examine, and report evidence with precision.