In this course, you will be presented with an overview of the principles and techniques for digital forensics investigation in the spectrum of file system analysis.
Learning Objectives
By the end of the course, students should be able to:
- Understand the process to perform a digital forensics investigation
- Identify and define file systems concepts, including EXT, FAT, and NTFS
- Conduct live and dead disk acquisitions
- Understand what happens when you delete a file
- Perform data carving and Steganographic techniques
- Properly check and execute malicious files
- Create a complete forensics tool kit
- Basic understanding and experience with professional tools
Framework Connections
Specialty Areas
- Digital Forensics
- Cyber Investigation
Feedback
If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.