Get Real!
  

RealSchedule  »  Course Outline

To schedule, contact us at 972-865-2290, or email us at sales@realsolutionstraining.com



Course Number:   RS-CF
Course Title:  
Computer Forensics
Scheduled DatesRegister
   November 29 - December 3, 2010  This class is guaranteed to run!
   January 10 - 14, 2011  This class is guaranteed to run!
Know someone who  
needs this course?
  
Length:   5 Day(s)

Compare To:

Description:
This course is designed to equip government and corporate investigators with the skills needed to safely locate and secure computer evidence. Forensics concepts and procedural skills are reinforced with quizzes and challenging group participation exercises.


What you will learn:
  • This class is designed to introduce the student to concepts, techniques, and tools providing a solid foundation in concepts related to the investigation, preservation, and processing of computer based evidence.
Audience:



Prerequisites:
Outline:
  1. • Computer crime overview and raid considerations
  2. • Operating systems and file systems
  3. o Difference between an Operating System and a file system
  4. o File systems supported by DOS, Win9x and NTx
  5. o Why we still use DOS in forensics
  6. • MSDOS commands
  7. o Internal and external commands
  8. o Directory structure and “Path”
  9. o Navigating between partitions and directories
  10. • Hardware, BIOS and CMOS
  11. o Types of hardware encountered
  12. o Role of the BIOS and CMOS
  13. o Information of interest in CMOS
  14. • Configuring & connecting hard drives
  15. o IDE
  16. o SCSI
  17. o SATA
  18. • Physical drive structure
  19. o Cylinder, Head, Sector addressing
  20. o Logical Block Addressing
  21. • Partitions
  22. o Primary
  23. o Extended/logical drives
  24. o Hidden
  25. • Boot process & Drive letter assignment
  26. o DOS and Win9x
  27. • Write blockers
  28. o Software
  29. o Hardware
  30. o DI's write blockers
  31. • Creating a control boot floppy
  32. • Creating a duplicate image
  33. • Computer data
  34. o Bits/Bytes
  35. o ASCII
  36. o Hexadecimal
  37. • FAT file system
  38. o Formatting a logical drive
  39. o Changes that occur when a file is saved
  40. o Changes that occur when file is deleted and recovering deleted files
  41. • NTFS file system
  42. o Formatting
  43. o Changes that occur when a file is saved
  44. o Changes that occur when file is deleted
  45. • Forensic examination topics
  46. o Date and time information (FAT and NTFS)
  47. o Long filenames
  48. o Recycle Bin
  49. o File types
  50. o Key word searches
  51. o Encryption
  52. Symmetric
  53. Asymmetric
  54. Win2K/XP EFS
  55. o Compression
  56. PK archives
  57. NTFS built-in compression
  58. Carving from unallocated and slack space
  59. Final practical
 
  

Code development by the instructors of RealSolutions Training
Site design by Image Fusion