Students will study the art of anti-forensics, which is the art of information hiding. The broad field of data hiding and anti-forensics will be explored with a specific concentration on cryptography (secret writing) and steganography (hidden writing). Basic principles of digital media will be studied in order to understand how digital images, audio and video can be manipulated and how such manipulation can be detected. Finally, introductory concepts about computer network investigations will be presented.
Learning Objectives
- Identify and describe Windows-based networks and security issues.
- Describe Incident Response best practices, tools, and related issues.
- Become familiar with the tools used for volatile data collection.
- Describe and classify the threats that Windows-based computer networks are confronted with.
- Examine and demonstrate techniques used to compromise networks.
- Identify the location on a Windows-based PC for digital artifacts related to an incident.
- Discuss and identify the location on a Windows-based network for digital artifacts related to an incident.
- Describe methods of anti-forensics.
- Identify issues related to forensic investigation of computer networks.
- Describe the operation and use of a packet sniffer in network investigations.
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Network Services
- Incident Response
- Vulnerability Assessment and Management
- Digital Forensics
- Cyber Investigation
- Collection Operations
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.