Course Overview
Learning Objectives
- Identify structures, and recover evidence from, the NTFS file system
- Identify structures, and recover evidence from, the EXT (Linux) file system
- Identify structures, and recover evidence from, the HFS+ (Mac) file system
- Identify structures encompassing the Macintosh and Linux boot processes
- Recover evidence from the Windows registry
- Recover evidence from an email and web investigation
- Demonstrate an understanding of the fundamentals of mobile device forensics
- Demonstrate an understanding of the fundamentals of solid state forensics
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Digital Forensics