Windows OS Forensics

所在平台: Coursera

课程主页: https://www.coursera.org/learn/windows-os-forensics

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Windows OS取证 课程概述:Windows OS取证课程涵盖Windows文件系统,包括FAT32、ExFat和NTFS。您将学习这些系统如何存储数据、文件写入磁盘后发生的事、文件从磁盘删除后的情况以及如何恢复已删除的文件。课程还将教您如何正确解读文件系统数据结构中的信息,从而让学生更好地理解这些文件系统的工作原理。掌握这些知识将使您能够正确验证来自多种取证工具的信息。 课程大纲: 1. **比特、字节与字节序** - 本模块解释了计算机取证中使用的各种编号方案。您将探索计算机取证中使用的编号方案,这一知识使学生能够在十六进制和二进制级别解读数据。这项技能对于验证取证软件工具至关重要,并让学生了解如何找到取证软件所显示的数据。这些信息在法庭诉讼中尤其有益。 2. **磁盘分区结构** - 本模块介绍主引导记录(MBR)和GUID分区表(GPT)之间的区别。该模块帮助学生理解如何在驱动器上定位分区和数据。取证学生学习如何解读主引导记录,并定位驱动器上每个卷的卷引导记录。 3. **FAT文件系统** - 本模块深入探讨FAT文件系统的结构。您将了解FAT文件系统如何将文件写入驱动器以及如何从驱动器删除文件。掌握这些知识后,考察人员可以恢复已删除的数据或从重新格式化的驱动器中恢复数据。 4. **NTFS文件系统** - 本模块将详细探讨NTFS文件系统。NTFS是取证检查的重要组成部分。本模块解释文件系统如何组织信息、数据在驱动器上的位置以及元数据存储的位置,以及在删除或创建文件时文件系统级别的变化。 5. **exFAT文件系统** - 本模块更详细地讲解exFAT文件系统的结构和布局,学习文件系统如何跟踪文件、存储文件元数据以及如何恢复已删除数据。 6. **Windows注册表取证** - 本模块探讨Windows注册表取证的复杂性和挑战。内容包括注册表的历史和功能,如何检查活动注册表、注册表文件在取证图像中的位置以及如何提取文件。通过使用取证工具检查文件,学生可以找到相关的证据,例如USB设备连接时间、最近使用的文件、程序最后运行时间和设置为启动时运行的程序。 本课程将为您提供有关Windows操作系统取证的重要知识,从而提升您的取证技能。

课程大纲

Name:Bits, Bytes and Endienness

Description:This module explains the various numbering schemas used throughout computer forensics. In this module, you'll explore the numbering schemas used in computer forensics. This knowledge allows the student to interpret data at the hex and binary levels. This skill is necessary to validate forensic software tools and gives the student an understanding of where to locate the data displayed by their forensic software. This information is notably beneficial for court proceedings.

Name:Disk Partition Schema

Description:A look at the master boot record and the GUID partition table. This module demonstrates the difference between the master boot record and the GUID partition table. This information gives the student an understanding of where to locate both partitions and data on the drive. The forensic student learns how to interpret the master boot record and locate the volume boot record for each volume on the drive.

Name:The FAT File System

Description:This module explores the structure of the FAT file system. This module covers the structure and layout of the FAT file system. The student develops an understanding of how the FAT file system writes a file to a drive and deletes a file from a drive. With this knowledge, the examiner can recover deleted data or recover data from a reformatted drive.

Name:The NTFS File System

Description:In this module, you'll explore the details of the NTSF file system. NTSF is a crucial component of forensic examinations. This module explains how the file system organizes information and where data is located on the drive. It also covers where the metadata for the file is stored and the changes that occur at a file system level when someone deletes or creates a file.

Name:The ex-fat File System

Description:Take a closer look at the details of the ex-FAT file system. In this module, the student learns the structure and layout of the ex-FAT file system, how the file system tracks files, where it stores the file metadata and how to recover deleted data.

Name:Windows Registry Forensics

Description:Explore the complexities and challenges of Windows Registry forensics. This module covers the history and function of the Registry. It includes how to examine the live Registry, the location of the Registry files on the forensic image and how to extract files. After examining the files with forensic tools, the student can locate relevant artifacts such as USB device connection times, recently used documents, program last run times and programs set to run at startup.

课程评论(0条)

课程详情

The Windows OS Forensics course covers windows file systems, Fat32, ExFat, and NTFS. You will learn how these systems store data, what happens when a file gets written to disc, what happens when a file gets deleted from disc, and how to recover deleted files. You will also learn how to correctly interpret the information in the file system data structures, giving the student a better understanding of how these file systems work. This knowledge will enable you to validate the information from multiple forensic tools properly.

课程标签

0人关注该课程

主题相关的课程