Forensic Investigator (Part 4 of 10): Data and Anti-Forensics
Interactive

Forensic Investigator (Part 4 of 10): Data and Anti-Forensics

Biz Library
Updated Feb 04, 2020

Dive into data acquisition to discover the differences between live and static acquisitions, as well as to learn about volatile data, or the data that should be acquired first once a system has been determined to be a crime scene. Additionally, explore the various tools and the necessary hardware and software required to carry out a successful investigation. Following an exploration of data acquisition, take a closer look at anti-forensics to understand the techniques criminals may use to make your acquisition more difficult including encryption and file deletion. Then, learn about the countermeasures that can be implemented to overcome acquisition obstacles including password crackers and undelete utilities. This course contains the following lessons:


Lesson 1:

  • Data Acquisition
  • Volatile Data
  • Non-Volatile Data
  • Do We Need Copies?
  • Copies or Duplicates
  • Chain of Custody
  • Chain of Custody Form
  • Forensic Tools
  • Software Forensic Tools for Acquisition
  • Hardware Forensic Tools for Acquisition.

Lesson 2:

  • Live Acquisition
  • Live Acquisition Common Items
  • Which Volatile Data First
  • Live Acquisition Steps
  • Live Acquisition Tools
  • Live Acquisition Common Mistakes
  • Locard's Exchange Principle.

Lesson 3:

  • Static Acquisition
  • Write Blockers
  • Destination Media
  • Static Acquisition Tools
  • Acquisition Methods
  • Disk to Disk
  • Disk to Image
  • Static Acquisition Image Formats
  • Format
  • Sparse and Logical Acquisition
  • Are the Copies Good?.

Lesson 4:

  • Anti-Forensics
  • Why Do They Use Anti-Forensics?
  • Techniques Used
  • Case Study
  • Tools and Techniques Used.

Lesson 5:

  • Techniques Used: An In-Depth Look
  • Password Protection
  • Password Cracking Techniques
  • Deleting Files
  • Encryption
  • Rootkits
  • Rootkit Types.

Lesson 6:

  • Countermeasures
  • Challenges
  • Challenges.