|
|
|
|
Course Number:
|
RS-CF |
 |
Course Title:
|
Computer Forensics |
| Scheduled Dates | Register |
November 29 - December 3, 2010
|
|
January 10 - 14, 2011
|
|
Know someone who
needs this course? |
 |
|
|
Length:
|
5 Day(s)
|
|
Description:
This course is designed to equip government and corporate investigators
with the skills needed to safely locate and secure computer evidence.
Forensics concepts and procedural skills are reinforced with quizzes and
challenging group participation exercises.
What you will learn:
- This class is designed to introduce the student to concepts, techniques, and tools providing a solid foundation in concepts related to the investigation, preservation, and processing of computer based evidence.
Audience:
Prerequisites:
Outline:
-
- • Computer crime overview and raid considerations
- • Operating systems and file systems
- o Difference between an Operating System and a file system
- o File systems supported by DOS, Win9x and NTx
- o Why we still use DOS in forensics
- • MSDOS commands
- o Internal and external commands
- o Directory structure and “Path”
- o Navigating between partitions and directories
- • Hardware, BIOS and CMOS
- o Types of hardware encountered
- o Role of the BIOS and CMOS
- o Information of interest in CMOS
- • Configuring & connecting hard drives
- o IDE
- o SCSI
- o SATA
- • Physical drive structure
- o Cylinder, Head, Sector addressing
- o Logical Block Addressing
- • Partitions
- o Primary
- o Extended/logical drives
- o Hidden
- • Boot process & Drive letter assignment
- o DOS and Win9x
- • Write blockers
- o Software
- o Hardware
- o DI's write blockers
- • Creating a control boot floppy
- • Creating a duplicate image
- • Computer data
- o Bits/Bytes
- o ASCII
- o Hexadecimal
- • FAT file system
- o Formatting a logical drive
- o Changes that occur when a file is saved
- o Changes that occur when file is deleted and recovering deleted files
- • NTFS file system
- o Formatting
- o Changes that occur when a file is saved
- o Changes that occur when file is deleted
- • Forensic examination topics
- o Date and time information (FAT and NTFS)
- o Long filenames
- o Recycle Bin
- o File types
- o Key word searches
- o Encryption
- Symmetric
- Asymmetric
- Win2K/XP EFS
- o Compression
- PK archives
- NTFS built-in compression
- Carving from unallocated and slack space
- Final practical
|
|
|