If you are interested in Digital Forensics, watch Technical Instructor, Dennis Thibodeaux, share the following modules in this study session:
The study session will include the following modules:
PART 1: PREPARATION FOR FORENSIC RESPONSE
Response team roles
Four types of evidence
US Federal Rules of Evidence
PART 2: SCOPE OF THE INVESTIGATION
First Responder best practices: Corporate vs. criminal cases
Locard’s Exchange Principle
Guidance from NIST, ACPO, US Department of Justice
Analysis of the compromised system
PART 3: THE INVESTIGATOR’S TOOLKIT
Incident response tools
Laboratory tools
Commercial DFIR software demo: FTK Imager
Open-source DFIR software demo: CAINE
DFIR tool standards and testing
PART 4: CAPTURING AND PRESERVING EVIDENCE
SWGDE procedure references
Capturing volatile data
Capturing persistent data
File carving and data extraction
PART 5: REVIEW AND CONCLUSION
The major goal: Admissibility of evidence
Professional development: Certifications and continuing education