Practical Digital Forensics (2025, Hindi)

所在平台: Udemy

课程主页: https://www.udemy.com/course/practical-digital-forensics-2025-hindi/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** 实用数字取证 (2025, 印地语) **课程概述:** 本课程专为希望掌握数字和网络取证基础知识的学生、年轻专业人士和技术爱好者设计,以一种对初学者友好的印地语教学方式,通过实践操作学习,避免陷入复杂的理论。 **课程内容:** * **数字取证流程:** * 证据链(Chain of Custody) * 证据采集:实时与离线 * 创建磁盘数字映像 * 处理磁盘映像以提取痕迹 * 从磁盘恢复已删除文件 * 收集数字取证痕迹(浏览器活动、最近打开文件、已安装程序、已执行程序、用户详细信息) * **Windows 事件日志:** * 事件日志提取以重建时间线 * 使用 Event Log Viewer 进行日志分析 * 使用 Log Parser 和 Log Parser Lizard 进行高级分析 * 使用 Hayabusa 的 Sigma 规则进行威胁狩猎 * **内存取证:** * Dumping 内存 (Linux 和 Windows) * 使用 Volatility 进行内存转储分析 * 使用 Volatility Workbench * 从内存中恢复数字取证痕迹(进程内存、进程二进制文件、打开的文件描述符、网络连接、进程层级) * **案例研究:** Cridex Malware Investigation * **网络取证:** * 使用 Redline 进行实时采集和快速分析 * 使用 Wireshark 捕获和分析网络流量 * HTTP 流量分析和对象提取 * TCP/UDP 流重构以揭示完整的通信过程 * **案例研究:** Redline Infostealer Malware Traffic Analysis * **案例研究:** Phishing Attack Traffic Analysis * 使用 Network Miner 进行网络取证以恢复痕迹 * 使用 CapAnalysis 和 Xplico 进行流量趋势和异常值定位的宏分析 * 使用 Master Parser 和 DeepBlue CLI 进行威胁狩猎 * 使用 Sysmon 进行日志丰富 * **沙箱及应用:** * **隔离沙箱:** Sandboxie, Firejail, SquareX * **恶意软件分析沙箱:** Any run, Cuckoo, Joe Sandbox **课程亮点:** 本课程侧重于实战技能,为您提供解决取证挑战的实践知识。通过 GitHub 仓库提供演示录屏和练习文件,以巩固学习。 **学习目标:** 完成课程后,您将对数字和网络取证有扎实的基础,并准备好迈出进入这一激动人心的领域的第一步! **先决条件:** 无需任何取证经验,只需一台电脑和学习的意愿。现在就开始您的学习之旅吧!

课程评论(0条)

课程详情

Dive into the world of Practical Digital Forensics with this beginner-friendly course in Hindi! This course is designed for students, young professionals, and tech enthusiasts who want to learn the basics of digital and network forensics through hands-on practice without getting lost in complex theory.Course covers the following:Digital Forensics ProcessChain of CustodyEvidence Acquisition: Live and DeadCreate digital image of a diskProcessing disk image for artifactsRecovering deleted files from DiskCollecting Forensics artifacts (browser activity, recently opened files, installed programs, executed programs, user details)Windows Event LogsEvent Log extraction to reconstruct TimelineLog Analysis with Event Log ViewerAdvanced analysis with Log Parser and Log Parser LizardThreat Hunting in Logs with HayabusaSigma rules for detectionDumping RAM for Linux and Windows machinesRAM Dump Analysis with VolatilityWorking with Volatility WorkbenchRecovering Forensics Artifacts from Memory (Process memory, Process Binary, Open File Descriptors, Network Connections, Process Hierarchy)Case Study: Cridex Malware InvestigationRedline for Live Acquisition and quick analysisNetworking Traffic capture and Analysis using WiresharkHTTP Traffic analysis and object extractionTCP/UDP Stream reconstruction to uncover complete exchangeCase Study: Redline Infostealer Malware Traffic AnalysisCase Study: Phishing Attack Traffic AnalysisNetwork Forensics to recover artifacts with Network MinerMacroanalysis to locate traffic trends and outliers: CapAnalysis and XplicoThreat hunting with Master Parser and DeepBlue CLILog Enrichment with SysmonSandboxes and their usageContainment Sandboxes: Sandboxie, Firejail, SquareXMalware Analysis Sandboxes: Any run, Cuckoo, Joe SandboxThe course focuses on real-world skills, equipping you with practical knowledge to solve forensic challenges. You'll also get access to demo recordings and practice files through a GitHub repository to reinforce your learning.By the end of this course, you'll have a solid foundation in digital and network forensics and be ready to take your first steps into this exciting field!No prior experience in forensics is required-just a computer and a willingness to learn. Start your journey today!

课程标签

0人关注该课程

主题相关的课程