|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/digital-forensics-concepts
课程评论:没有评论
课程名称:数字取证概念 概述:在数字取证概念课程中,您将学习与计算机取证相关的法律考虑以及如何识别、收集和保存数字证据。该课程深入探讨与数字取证相关的科学原理,并详细介绍现场初步评估、关键词列表、grep、文件哈希、报告写作以及数字取证检查工作。 大纲: - **数字取证简介**:本模块提供计算机取证职业的广泛概述,探讨与数字取证相关的方法论。同时,学生会获得在整个课程中使用的开源取证工具。 - **法律考虑和搜索权限**:探讨适用于数字取证的法律,包括州和联邦法律,以及道德方面的考虑。本模块展示了搜索令和保留请求中常见的信息,以及搜索权限范围和同意搜索的限制。 - **调查过程**:介绍数字取证的科学原理,讲述证据转移的过程、证人和专家证人之间的区别,以及“大数据”的关注点和解决方案。 - **识别和收集数字证据**:该模块专注于物理证据处理,帮助学生了解在现场前、期间和后如何管理物理证据,包括如何准备和标记数字证据。 - **证据保留/现场初步评估**:探讨数字设备的初步评估,了解如何有效保护易失数据和避免收集不必要的设备。 - **哈希值和文件哈希**:学习哈希值和哈希算法的应用,掌握如何利用哈希值来筛选调查文件。 - **创建磁盘映像**:强调创建磁盘映像的重要性,包括避免交叉污染、验证工具和书写器的正确使用。 - **关键词和grep搜索**:学习如何使用自动化工具进行关键词搜索,建立关键词列表及grep搜索的基础知识。 - **网络基础**:介绍计算机取证调查员需了解的网络基本概念,包括IP地址和MAC地址的功能及其在网络取证中的重要性。 - **报告与同行评审**:讨论报告写作和同行评审的重要性,包括在最终报告中应包含和不应包含的信息。 - **数字取证项目**:通过具体项目将所学知识应用于实践。 该课程全面覆盖数字取证的基本概念与技术,为有志于此领域的学员提供了实用的知识和技能。
Name:Introduction to Digital Forensics
Description:This introductory course provides a broad overview of computer forensics as an occupation by exploring methodologies used surrounding digital forensics. In addition, the student acquires open-source forensic tools to use throughout this path.
Name:Legal Considerations and search authority
Description:In this module, you'll explore the laws that apply to digital forensics. Multiple state and federal laws apply to the field of digital forensics, as well as ethical concerns. This module demonstrates information commonly needed in a search warrant and a preservation request. The scope of search authority is covered, as well as the limitations of a consent search and guidelines surrounding wiretaps.
Name:The Investigation Process
Description:An introduction to the scientific principles of digital forensics. This module covers scientific principles that apply to digital forensics. The student learns about transfer of evidence, the difference between a witness and an expert witness and "big data" concerns and solutions.
Name:Recognizing and Collecting Digital Evidence
Description:Prepare for the practical side of forensic examinations with this module on physical evidence handling. In addition to forensic examinations, most digital investigators must understand how to manage physical evidence before, during and after leaving the scene. This module explores what to bring to a scene and how to prepare and label digital evidence for documentation purposes. You'll also examine how to collect and preserve the evidence for transportation and secure storage.
Name:Preservation of evidence/On scene triage
Description:Explore the details of digital device triage. Triaging a digital device is essential knowledge. Proper on-scene triage prevents the loss of volatile data and the collection of unnecessary devices. This module discusses capturing RAM, recognizing and dealing with encryption and destructive processes and triaging devices with a forensic boot media.
Name:Hash values and file hashing
Description:A look at hash values and hash algorithms. In this module, the student learns how to use hash values as a way to include or exclude files from an investigation. This includes a discussion of different types of hash algorithms and how to hash individual files versus hashing drives.
Name:Creating a disk image
Description:In this module, you'll explore the importance of creating a disk image. Forensic examiners need to be meticulous in their work to avoid cross-contamination when creating a bit-stream copy. This module explains the importance of sterilizing media, how to validate tools, proper application of the write-blocker and validating the forensic bit-stream copy.
Name:Keyword and grep searches
Description:Explore the details of keyword and grep searches. How to conduct a keyword search using automated tools and how to establish a keyword list is covered in this module. The student receives an overview of grep, as well as completing a grep search using an automated tool.
Name:Network Basics
Description:A look at network basics for the computer forensics investigator. This module describes what a network is, how it functions, what IP addresses are and an IP address’s function on the network. This module also explores what a MAC address is and why it is vital to network forensics. Internet protocols are also covered.
Name:Reporting and Peer Review
Description:A look at the importance of reporting and peer review. Report writing and peer review are of utmost importance. In this module, the student examiner learns what information to include and what does not belong in a final report. The student views several example reports, as well as generates a report using forensic software.
Name:Digital Forensics Project
Description:
In the Digital Forensics Concepts course, you will learn about legal considerations applicable to computer forensics and how to identify, collect and preserve digital evidence. This course dives into the scientific principles relating to digital forensics and gives you a close look at on-scene triaging, keyword lists, grep, file hashing, report writing and the profession of digital forensic examination.