CIRCL Training and Technical Courses

File-system Post-mortem Forensic Analysis

Forensic analysis is based on the principle that every action leaves a trace. This course shows participants how to determine what happened by analyzing the layers from physical media and file systems through to applications.

Learning goals

  • Perform disk acquisition correctly.
  • Analyze NTFS and FAT file systems.
  • Analyze Microsoft Windows artifacts.
  • Find evidence in communication applications, including browser and chat history.

Audience and prerequisites

This course is intended for IT department staff and local incident response teams. Knowledge of operating systems and IT security is required.

Practical information

Top