FOR500.6: Workbook
Book information
Description
FOR500.6: WorkbookOverviewNothing will prepare you more as an investigator than a full hands-on challenge that requires you to use the skills and knowledge presented throughout the week. In the morning, you will have the option to work in teams on a real forensic case. Students will be provided new evidence to analyze, and the exercise will step you through the entire case flow, including proper acquisition, analysis, and reporting in preparation for a possible trial. Teams will work on the case with the objective of profiling computer usage and discovering the most critical pieces of evidence to present.This complex case will involve an investigation into one of the most recent versions of the Windows Operating System. The evidence is real and provides the most realistic training opportunity currently available. Solving the case will require that students use all of the skills gained from each of the previous sections.The section will conclude with a mock trial involving presentations of the evidence collected. The team with the best in-class presentation and short write-up wins the challenge...and the case!
Similar books
FOR500.5: Core Windows Forensics Part IV: Internet Browsers
2017 · PDF
FOR500.3: Core Windows Forensics Part II: USB Devices and Shell Items | FOR500.4: Core Windows Forensics Part III: Email, Key Additional Artifacts, and Event Logs
2017 · PDF
FOR500.1: Windows Digital Forensics and Advanced Data Triage | FOR500.2: Core Windows Forensics Part 1: Windows Registry Forensics and Analysis
2017 · PDF
SANS 560.6 - Penetration Test and Capture the Flag Workshop
2017 · PDF
SANS 560.5 - In-Depth Password Attacks and Web App Pen Testing
2017 · PDF
SANS 560.4 - Post-Exploitation and Merciless Pivoting
2017 · PDF
SANS 560.3 - Exploitation
2017 · PDF
SANS 560.2 - In-Depth Scanning
2017 · PDF