Forensic Investigator, Part 07 of 10: Database Forensics
Interactive

Forensic Investigator, Part 07 of 10: Database Forensics

LearnNow Online
Updated Aug 21, 2018

Course description

MySQL, Oracle or MS SQL server….which is it running? How do you know? Oracle may be the number one database on the market today, but what does that mean for us as investigators? Coming up, we will be looking at various database management systems and how they work with data. We will dive into Oracle databases, MySQL databases and MS SQL databases so we know where we can look for potential evidence. We will also take a look at some tools and techniques that will allow us to gather the data for our case against the perpetrators. This course is part of a series covering the EC-Council Computer Hacking Forensic Investigator (CHFI).

Each LearnNowOnline training course is made up of Modules (typically an hour in length). Within each module there are Topics (typically 15-30 minutes each) and Subtopics (typically 2-5 minutes each). There is a Post Exam for each Module that must be passed with a score of 70% or higher to successfully and fully complete the course.


Prerequisites

Recommended: Understanding of networking; How data flows from source and destination Computer security basics such as passwords, encryption and physical security Basic understanding of computing and computer systems Experience with various operating systems


Meet the expert

David Bigger

David Bigger is the lead trainer at Bigger IT Solutions. He has been information technology for a little over 20 years and has been training all over the US. He has worked with companies like US Military, Lockheed Martin, General Dynamics, Dominos Pizza, University of Utah and Expedia

Video Runtime

53 Minutes

Time to complete

73 Minutes

Course Outline

Database Forensics

Database Forensics (12:54)

  • Introduction (00:26)
  • Database Forensics (02:17)
  • Database Review (05:12)
  • Popular DBMS (04:39)
  • Summary (00:19)

Oracle (15:38)

  • Introduction (00:19)
  • Oracle (01:24)
  • Oracle Logical Structure (01:14)
  • Data Blocks (01:41)
  • System Change Number (SCN) (01:41)
  • Where to Look in Oracle (00:54)
  • System Global Area (03:23)
  • Where to Look in Oracle, Continued (03:47)
  • Oracle Forensic Tools (00:48)
  • Summary (00:22)

MySQL (13:21)

  • Introduction (00:20)
  • MySQL (01:36)
  • Data Directory (02:37)
  • Log Files for MySQL (04:02)
  • Were to Look in MySQL (01:31)
  • MySQL Forensic Tools (02:53)
  • Summary (00:19)

Microsoft SQL Server (11:27)

  • Introduction (00:24)
  • Microsoft SQL Server (01:44)
  • Data Storage (03:08)
  • Where to Look on MS SQL Server (03:18)
  • Tools for MS SQL Forensics (00:27)
  • SQL Server Management Studio (00:43)
  • ApexSQL (01:15)
  • Summary (00:25)
;