Forensic analysis is based on the principle that every action leaves a trace. This course shows participants how to determine what happened by analyzing the layers from physical media and file systems through to applications.
Learning goals
- Perform disk acquisition correctly.
- Analyze NTFS and FAT file systems.
- Analyze Microsoft Windows artifacts.
- Find evidence in communication applications, including browser and chat history.
Audience and prerequisites
This course is intended for IT department staff and local incident response teams. Knowledge of operating systems and IT security is required.
Practical information
- Duration: 8 hours
- Languages: English or German
- Materials: Digital Forensics training materials