
This course is intended to share my knowledge and to provide you with a learning guide on how to study Hard Disk Forensics. In this video, you'll be introduced to the Hard Disk conceptual model!
In this video, you'll learn about the Application Layer and why it is important to have this layer in our conceptual model.
In this video, you'll learn about how to use a conceptual model to learn different Filesystems. You will also learn to use different The Sleuth Kit (TSK) tools using this conceptual model.
In this video, you'll learn about what Partitions are and how they are organized using Partitioning Schemes. You'll also see a demo of how to use TSK tools to extract and analyze different partitions on a disk.
In this video, you'll learn about ATA disks and certain interesting ATA features like Host Protected Area (HPA) and Device Configuration Overlay (DCO) that are relevant from forensics' point-of-view.
Introduction: Welcome to my comprehensive course on Hard Disk Forensics! This course aims to provide a brief overview of all the essential concepts you need to learn to enter the world of Hard Disk Forensics. In just about 36 minutes, you will acquire a solid understanding and a map of resources to systematically learn and practice Hard Disk Forensics.
Course Overview:
In this course, I'll introduce you to a systematic conceptual model that plays a crucial role in understanding the various sub-systems analyzed in Hard Disk Forensics.
You'll learn about the basics of several key components, including Filesystems, The Sleuth Kit tools (the backbone of Autopsy), Partitions, Partition Tables, Partitioning Schemes, Data Link standards like ATA and SCSI (with a focus on ATA), and more.
Foundation for Mastery: This course will lay a strong foundation for your journey to mastering Hard Disk Forensics. With the knowledge gained, you'll be well-equipped to explore the fascinating world of digital investigations.
Systematic Conceptual Model: I'll start by defining a conceptual model with five layers:
Application Layer
Filesystem Layer
Volume Layer
Interface Layer
Physical Layer
Understanding the Layers: Throughout the course, I'll delve into the basics of the first four layers, providing you with valuable resources to explore each layer in depth. This systematic approach will enhance your comprehension and practical skills.
Key Resource: The primary book I have referenced for this course is "Filesystem Forensic Analysis" by Brian Carrier. This resource has been instrumental in shaping the content and knowledge shared in this course.
By the end of this course, you'll have the knowledge and tools to confidently navigate the realm of Hard Disk Forensics.