Computer Forensics Today
- Fundamentals and objectives of computer forensics, types of digital evidence
- Forensic readiness in organisations
- Legal frameworks and standards for digital evidence
The Forensic Investigation Process
- Phases before, during and after an investigation
- Securing and documenting evidence and maintaining the chain of custody
- Preparing the investigation report and presenting findings in court
Hard Disks and File Systems
- Structure of hard disks and SSDs, partitions and boot processes
- Understanding and analysing file systems on Windows, Linux and macOS
Data Acquisition and Duplication
- Live and offline acquisition, forensic image formats
- Verifying data integrity with hash values, write protection during acquisition
Overcoming Anti-Forensics Techniques
- Recovering deleted files and partitions
- Detecting and bypassing password protection, encryption, steganography and other obfuscation techniques
Windows Forensics
- Collecting volatile and non-volatile data, analysing memory
- Analysing the registry, event logs, browser artefacts and metadata
Linux and Mac Forensics
- Acquiring and analysing volatile and non-volatile data on Linux
- Examining forensic artefacts and logs on macOS
Network Forensics
- Collecting logs, correlating events and reconstructing attacks
- Analysing network traffic, investigating incidents in wireless networks
Malware Forensics
- Static and dynamic malware analysis in a controlled environment
- Tracing malware behaviour on systems and in the network
Investigating Attacks on Web Applications
- Analysing web server logs
- Detecting and tracing attacks such as SQL injection, cross-site scripting and directory traversal
Dark Web Forensics
- How the dark web and Tor work
- Finding and analysing traces of Tor browser usage on systems
Cloud Forensics
- Specifics and challenges of forensic investigations in the cloud
- Investigations in Amazon Web Services (AWS) and Microsoft Azure
Email and Social Media Forensics
- Analysing email headers and email histories, investigating email crimes
- Acquiring and analysing evidence from social networks
Mobile Forensics
- Logically and physically acquiring data from Android and iOS devices
- Analysing and documenting mobile artefacts
IoT Forensics
- Architecture and typical attacks on IoT devices
- Forensic examination of IoT devices and related data sources