
Explore how to handle volatile data, data that doesn't stay around and requires power to be useful, as a forensic investigator, and learn practical ways to deal with it.
Learn how to collect Windows volatile data on site, including system time, open files, shares, command history, clipboard contents, logged on users, mapped drives, and essential network information.
Learn to anticipate volatile data challenges in Windows and plan to collect, preserve, and present it in a court of law.
Explore non-volatile data in Windows systems and how investigators handle power-independent evidence. Learn why this data is easier to collect over time, but requires careful handling.
Learn to gather Windows non-volatile data through static acquisition, examining event logs, registry settings, browser history and cookies, thumb caches, slack space, and page file for forensic evidence.
Non-volatile data plays a crucial role in investigations, and applying a solid non-volatile data collection method helps build a strong case.
Explore how to locate and collect evidence on Linux machines, including key locations and techniques investigators use on site.
Explore linux forensics by locating log files in /var/log, examining authentication and failed login records, and using shell commands like grep, cat, and netstat to uncover evidence.
Identify locations to search for forensic evidence on Linux machines and leverage logs as valuable sources of information for investigations.
Perform mac forensics by identifying key indicators during an investigation and locating where to collect evidence on Macintosh systems.
Analyze macOS forensics by reviewing /var system logs—install, network, access, and printer activity—Safari history, and keychain clues using Spotlight and Time Machine.
Develop proficiency in Mac forensics with practice and baseline knowledge; the lecture highlights common places to look for evidence and how to approach Mac investigations.
Explore malware types and how harmful software can compromise your end devices, with a refresher on how you may become a target.
Explore malware forensics by identifying viruses, trojans, worms, rootkits, and ransomware, infection vectors, and components, then analyze indicators such as open ports, suspicious processes, and traffic patterns.
Explore popular malware—viruses, worms, ransomware, and root kits—and learn how they can wreak havoc on networks and systems.
Detect and address a system compromise by performing static analysis, then explore the tools and techniques used to conduct it.
Apply static and dynamic malware analysis in a dedicated isolated lab, using tools like VirusTotal, hashing, and strings to identify malware and its dependencies.
Conduct static analysis to determine if software has malicious intent, applying techniques and identifying resources like a dedicated machine, then outline the next steps after the analysis.
Explore dynamic analysis to observe how malware behaves by running code and monitoring its actions, distinguishing it from static analysis.
Perform dynamic analysis of malware in a secure, isolated environment by monitoring registry changes, processes, ports, and network traffic with tools like RegShot, Process Explorer, Wireshark, and NetSim.
Perform dynamic analysis to understand what happens in the background of malware, using Wireshark, registry monitors, and network simulators to assist the investigation.
Refresh your database fundamentals with a brief review of how databases work and the different types you may encounter, especially if years have passed since your last project.
Explore database forensics foundations by reviewing relational database schemas, tables, rows, and columns, and compare Oracle, MySQL, and Microsoft SQL Server to understand SQL-based data relationships.
Understand diverse databases without being a database expert by learning their language and how to interpret what the database shows. Troubleshoot small problems to become a better forensic investigator.
Explore Oracle database as a management system and identify where to look and which tools investigators can use to find potential evidence.
Explore Oracle forensics basics: table spaces, data blocks, and SCN–driven changes, plus SGA components, redo logs, flashback, recycle bin, and tools like log miner and ora block.
Explore how Oracle databases support investigations by examining the flashback database, recycle bin, and the system global area for potential evidence.
Identify open source databases and examine Maia's QOL database to locate evidence, then apply recommended tools to perform these forensic tasks.
Explore how a forensic investigator uses MySQL artifacts: data directory, logs (error, general, relay), undo/redo logs, information_schema, and mysqldump backups for evidence.
Explore MySQL forensic techniques for open source data, including locating logs, understanding the database structure, and using investigation tools to analyze Maia's Keywell data.
Compare Oracle with Microsoft SQL Server and learn where to look and what tools gather essential information about this database management system.
Investigate SQL Server data storage, including primary MDF and secondary NDF files and transaction logs (LDF), and use SQL Server Management Studio and ApexSQL Audit for forensic analysis.
Compare Microsoft SQL Server with Oracle and MySQL, identify key places to look, and show how the SQL database stores information, including log files and operating system logs.
Explore how data travels from point A to point B along network cables and the devices needed. Skip this networking review if you already hold Network Plus or CCMA.
Explore core networking concepts for forensics, including IP addressing (IPv4 and IPv6), DNS, DHCP, routers, firewalls, IDS/IPS, and routing, and how devices yield evidentiary data.
Analyze IP addressing and routing on networking devices to build a clear picture for the investigation. Identify the data needed for evidence gathering and review devices involved in the network.
Learn where to look for evidence in network forensics and what investigators search for with routing knowledge guiding case work.
Explore network forensics by analyzing logs as records, ensuring immutable, admissible evidence, and using event aggregation and correlation with centralized logging and security information and event management to identify breaches.
Extract and analyze network logs as the primary evidence, verify their legality, ensure source accuracy, and test their integrity to support a network investigation.
Begin a network investigation by examining firewalls, with a focus on Check Point firewalls and Cisco firewalls.
Explore how firewalls filter traffic at entry and exit points, compare Checkpoint and Cisco firewalls, and interpret logs with ports, timestamps, and severity levels to detect and classify security events.
Examine how common firewalls filter inbound and outbound traffic and identify how data flows leave evidence that investigators can analyze for forensic insights.
Explore how firewalls and ids solutions provide investigators with data to comb through for evidence, and review popular ids solutions in this topic.
Analyze intrusion detection system data to extract evidence from Juniper and Checkpoint IDS logs, using security manager and smart view tracker to map timestamps, IPs, attack types, and severity.
Place sensors in line or across the network, gather and analyze data, and use the checkpoint and junip radius to identify where to look with the necessary tools.
Explore how a router channels network traffic and serves as the ideal spot for investigators to uncover evidence by examining data from router vendors.
Investigate router logs from Cisco IOS and Juniper Junos to gather evidence, using centralized logging for date and time stamps, source IP address and destination IP address, and event details.
Explore router analysis in network investigations, focusing on Cisco and Juniper, and learn where to find vendor-specific syntax and codes that support evidence gathering.
Perform live analysis on real-time data to detect suspicious traffic using lab analysis, and apply practical tools and techniques for forensic investigations.
In this live lab analysis, learn to capture real-time network traffic with a sniffer and promiscuous mode, using Wireshark to filter evidence and localize suspicious activity.
Live analysis provides real-time, up-to-the-second data for investigations. On-site teams use tools and techniques to capture evidence when an attack is ongoing.
Explore how e-mail works, where data routes, and how servers, protocols, and clients form the foundational knowledge an investigator uses.
Explore how email uses a client-server architecture, with smtp for outgoing mail and pop3/imap for retrieval, including ports 25, 110, 143 and server-side folders.
Identify email protocols, tracing steps, and where to look to follow how emails flow, enabling efficient information discovery for your investigation.
Learn what crimes can be committed using e-mail and what tools investigators use to analyze e-mail communications.
Investigate email crimes like identity fraud, cyber stalking, child abduction, and human trafficking, and learn phishing, spam, and malware exploitation with forensic tools to recover and analyze emails.
Tackle email investigations despite occasional tedium, and leverage the right tools to catch suspects and drive their capture, delivering a huge payoff.
Learn where to find email header information to gain specific evidence from individual messages, beyond what server logs reveal.
Analyze email headers to trace origin and routing using IPs, date and time stamps, and message IDs; view headers in Outlook, Gmail, and Yahoo, and correlate with logs and archives.
Explore popular email clients and locate header information, then correlate header data with network data to advance our forensic investigation.
Computer Security and Computer Investigations are changing terms. Many systems are built on a regular basis for computer investigations, be it cyber fraud, forensic analysis, cyber audits, or even basic electronic data recovery. The methods and techniques discussed in this class will train students to conduct computer investigations using revolutionary digital forensics technology.
Get certified in using forensically sound investigative techniques in order to evaluate the scene, collect and document all relevant information, interview appropriate personnel, maintain chain-of custody, and write a findings report on various levels of computer attacks.
With this course, a professional can feel confident about his knowledge and ability to analyze any security flaws that may arise in the system. REGISTER TODAY!