SDF: Shimcache Forensics

所在平台: Udemy

课程主页: https://www.udemy.com/course/sdf-shimcache-forensics/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:SDF:Shimcache取证 课程概述:欢迎参加数字取证生存系列课程。本课程旨在通过学习如何使用Windows Shimcache数据来证明文件使用和了解,帮助你成为一名更优秀的计算机取证检查员,整个课程时长大约为一个小时。与之前的SDF课程一样,课程采用实践学习的方式。课程开始于Windows Shimcache的基础知识,帮助学员理解该工件的工作原理。 随后,学员将进行多个验证练习,以观察用户活动如何影响Windows Shimcache证据。最后一部分将教授学员如何使用社区开发的免费DFIR取证工具来检查Shimcache证据。课程结束时,学员将对如何将Windows Shimcache作为证据使用有扎实的理解,了解影响Shimcache的用户行为类型,并掌握Windows Shimcache取证工具的使用。 无论是专家还是初学者都会从这门课程中受益。我们采用SDF方式教授的真实计算机取证技能,学员可以使用我们的方法或任何取证工具进行实践。因此,学员不仅会学习Windows Shimcache的使用,还将掌握一种方法,以应对未来可能出现的问题。课程要求学员使用运行Windows 8或Windows 10的个人电脑。我们使用的取证工具均为免费提供,因此除了你的笔记本电脑和操作系统,仅需有成为更好计算机取证检查员的愿望。

课程评论(0条)

课程详情

Welcome to the Surviving Digital Forensics series. This class is focused on helping you become a better computer forensic examiner by understanding how to use Windows Shimcache data to prove file use and knowledge - all in about one hour. As with previous SDF classes you will learn by doing. The class begins with Windows Shimcache fundamentals and will provide an understanding of how the artifact works. Then students delve into several validation exercises to observe how user driven activity affects Windows Shimcache evidence. The last section teaches students how to use freely available DFIR community built forensic tools to examine Shimcache evidence. By the end of the class students will have a solid understanding of how to use the Windows Shimcache as evidence, understand the types of user behaviors that affect the Shimcache and know how to use Windows Shimcache forensic tools. Expert and novice computer forensic examiners alike will gain from this class. Since we are doing it the SDF way we are going to teach you real computer forensic skills that you can apply using our method or with any forensic tool you choose. Therefore you are not just going to learn about the Windows Shimcache but you will learn a method you can use to answer questions that may come up in the future. A PC running Windows 8 or Windows 10 is required for this course. The forensic tools we use are all freely available, so beyond your laptop and operating system all you need is the desire to become a better computer forensic examiner.

课程标签

0人关注该课程

主题相关的课程