Covers theory of forensic procedures, review of identification, imaging, and authentication, review of FAT file system, NTFS, EXT3, and HFS+ file systems, partitioning, Window’s registry analysis, email and web history analysis, mobile and solid state forensics.
Learning Objectives
- Identify structures, and recover evidence from, the NTFS file system
- Identify structures, and recover evidence from, the EXT (Linux) file system
- Identify structures, and recover evidence from, the HFS+ (Mac) file system
- Identify structures encompassing the Macintosh and Linux boot processes
- Recover evidence from the Windows registry
- Recover evidence from an email and web investigation
- Demonstrate an understanding of the fundamentals of mobile device forensics
- Demonstrate an understanding of the fundamentals of solid state forensics
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Digital Forensics
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.