FOR500.1: Windows Digital Forensics and Advanced Data Triage | FOR500.2: Core Windows Forensics Part 1: Windows Registry Forensics and Analysis
Book information
Description
FOR500.1: Windows Digital Forensics and Advanced Data TriageOverviewThe Windows Forensic Analysis course starts with an examination of digital forensics in today's interconnected environments and discusses challenges associated with mobile devices, tablets, cloud storage, and modern Windows operating systems. Hard drive sizes are increasingly difficult to handle appropriately in digital cases. Being able to acquire data in an efficient and forensically sound manner is crucial to every investigator today. Most fundamental analysts can easily image a hard drive using a write blocker. In this course, we will review the core techniques while introducing new triage-based acquisition and extraction capabilities that will increase the speed and efficiency of the acquisition process. We will demonstrate how to acquire memory, the NTFS MFT, Windows logs, Registry, and critical files that will take minutes to acquire instead of the hours or days currently spent on acquisition.We will also begin processing our collected evidence using stream-based and file-carving-based extraction capabilities that employ both commercial and open-source tools and techniques. Seasoned investigators will need to know how to target the specific data that they need to begin to answer fundamental questions in their cases.FOR500.2: Core Windows Forensics Part 1: Windows Registry Forensics and AnalysisOverviewOur journey continues with the Windows Registry, where the digital forensic investigator will learn how to discover critical user and system information pertinent to almost any investigation. Each examiner will learn how to navigate and examine the Registry to obtain user profile data and system data. The course teaches forensic investigators how to prove that a specific user performed keyword searches, executed specific programs, opened and saved files, perused folders, and used removable devices.Data is moving rapidly to the cloud, constituting a significant challenge and risk to the modern enterprise. Cloud storage applications are nearly ubiquitous on both consumer and business systems, causing interesting security and forensic challenges. In a world where some of the most important data is only present on third-party systems, how do we effectively accomplish our investigations? In this section we will dissect OneDrive, Google Drive, G Suite, Dropbox, and Box applications, deriving artifacts present in application logs and left behind on the endpoint. Detailed user activity, history of deleted files and discovery of cloud contents are all possible. Solutions to the very real challenges of forensic acquisition are also discussed. Understanding what can be gained through analysis of these popular applications will make investigations of less common cloud storage solutions easier when encountered.Throughout the section, investigators will use their skills in a real hands-on case, exploring the evidence and analyzing evidence.
Similar books
FOR500.6: Workbook
2017 · PDF
FOR500.5: Core Windows Forensics Part IV: Internet Browsers
2017 · PDF
FOR500.3: Core Windows Forensics Part II: USB Devices and Shell Items | FOR500.4: Core Windows Forensics Part III: Email, Key Additional Artifacts, and Event Logs
2017 · PDF
SANS 560.6 - Penetration Test and Capture the Flag Workshop
2017 · PDF
SANS 560.5 - In-Depth Password Attacks and Web App Pen Testing
2017 · PDF
SANS 560.4 - Post-Exploitation and Merciless Pivoting
2017 · PDF
SANS 560.3 - Exploitation
2017 · PDF
SANS 560.2 - In-Depth Scanning
2017 · PDF