USB devices have become part of many forensic investigations and penetration tests. In this course, USB Forensics: Writeblocking and Impersonation, you'll learn USB forensics and penetration testing with the USB forensics writeblocking and impersonation. First, you'll explore easily and cheaply writeblocking USB mass storage devices in Linux. Next, you'll create an affordable USB pocket writeblocker. Finally, you'll discover how to build a USB impersonator that can bypass endpoint security software. By the end of this course, you'll know how to writeblock USB drives both on your Linux forensics workstation and using a small device while on the go.
Learning Objectives
- Software Write Blocking with Udev Rules
- Hardware Write Blocker Based on VNC
- USB Impersonation
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Digital Forensics
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.