|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/sdf-proving-file-use-knowledge-part-2-prefetch/
课程评论:没有评论
课程名称:SDF: Windows Prefetch Forensics 概述:欢迎参加《数字取证生存系列》课程。本课程旨在帮助您成为更优秀的计算机取证 examiner,通过了解如何使用Windows Prefetch数据来证明文件的使用和了解,课程时间约为一个小时。和以往的SDF课程一样,您将通过实践学习。本课程首先介绍Windows Prefetch的基础知识,帮助您理解该伪造的数据如何工作。随后,学生将进行多个验证练习,以观察用户活动如何影响Windows Prefetch证据。最后一部分教学生如何使用一些由DFIR社区开发的免费取证工具来检查Prefetch证据。课程结束时,学生将对如何作为证据使用Windows Prefetch有深入了解,理解影响Prefetch的用户行为类型,并掌握Windows Prefetch取证工具的使用。无论是专家还是新手计算机取证 examiner,均可从本课程中受益。我们将以SDF的方式教学,教授您真实的计算机取证技能,这些技能不仅适用于我们的方法,也可以与任何您选择的取证工具结合使用。因此,您不仅将学习Windows Prefetch,还将掌握一种可以在未来回答相关问题的方法。本课程需要一台运行Windows 8或Windows 10的PC,所使用的取证工具均为免费提供,因此除了您的笔记本电脑和操作系统外,只需有提升自我的渴望即可。
Welcome to the Surviving Digital Forensics series. This class is focused on helping you become a better computer forensic examiner by understanding how to use Windows Prefetch data to prove file use and knowledge - all in about one hour. As with previous SDF classes you will learn by doing. The class begins with Windows prefetch fundamentals and will provide an understanding of how the artifact works. Then students delve into several validation exercises to observe how user driven activity affects Windows prefetch evidence. The last section teaches students how to use several freely available DFIR community built forensic tools to examine prefetch evidence. By the end of the class students will have a solid understanding of how to use the Windows prefetch as evidence, understand the types of user behaviors that affect the prefetch and know how to use Windows prefetch forensic tools. Expert and novice computer forensic examiners alike will gain from this class. Since we are doing it the SDF way we are going to teach you real computer forensic skills that you can apply using our method or with any forensic tool you choose. Therefore you are not just going to learn about the Windows prefetch but you will learn a method you can use to answer questions that may come up in the future. A PC running Windows 8 or Windows 10 is required for this course. The forensic tools we use are all freely available, so beyond your laptop and operating system all you need is the desire to become a better computer forensic examiner.