|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/surviving-digital-forensics-windows-shellbags/
课程评论:没有评论
课程名称:数字取证生存指南:Windows Shellbags 概述:欢迎参加数字取证生存系列课程。本系列旨在帮助您提升计算机取证检查员的技能,每节课约一小时。课程将深入探讨如何利用Windows Shellbag记录来证明文件的使用和知识。Shellbag记录由特定用户活动生成,可以显示用户在计算机系统上的导航路径及操作时间,这是一种非常强大的证据!课程采用实践学习的方式,开始时简要介绍主题,然后设置取证系统并进行实践。学习过程将使用低成本和无成本的计算机取证工具,使所有水平的计算机取证检查员都能受益。课程内容包括: 1. 欢迎与数字取证生存系列简介 2. 如何充分利用课程 3. Windows Shellbags概述 4. 深入探讨Shellbags 5. 设置取证系统 6. 验证实操 01 - 本地系统活动 7. 验证实操 02 - 连接的USB设备 8. 验证实操 03 - 网络驱动器 9. 学生实操 10. 学生测验 11. 报告选项 12. 复习 13. 结束与感谢 该课程需要运行Windows 7或Windows 8的电脑,并需具备管理员权限。学员需使用一台不包含重要数据的测试机。所有使用的取证工具均为免费提供,因此只需具备操作系统和提升计算机取证技能的愿望。
Welcome to the Surviving Digital Forensics series. This series is focused on helping you become a better computer forensic examiner by teaching core computer forensic skills - all in about one hour. In this class examine how to use Windows Shellbag records to help prove file use and knowledge. Shellbag records are created by certain user activity and can be used to show where a user has navigated to on a computer system and when they did so. Very powerful evidence! As with previous SDF classes you will learn by doing. The class begins with a brief overview of the issue at hand. Then we set up our forensic systems and off we go. Learning is hands on and we will use low cost and no cost computer forensic tools to do so. Expert and novice computer forensic examiners alike will gain from this class. Since we are doing it the SDF way we are going to teach you real computer forensic skills that you can apply using our method or customize to meet your needs. You will learn how you can use freely available forensic tools, all GUI based, to extract and analyze Windows Shellbag evidence. Class Outline 1. Introduction and Welcome to the SDF series 2. Getting the most out of the class 3. Windows Shellbags - an overview 5. Shellbag Deep Dive 6. Setting up your forensic system 7. Validation practical 01 - local system activity 8. Validation practical 02 - attached USBs 9. Validation practical 03 - networked drives 10. Student Practical 11. Student Quiz 12. Reporting options 13. Review 14. Conclusion & thank you A PC running Win7 or Win8 is required for this course. You need admin rights to the system. The system itself should be a test system containing no critical data. The forensic tools we use are all freely available, so beyond your operating system all you need is the desire to become a better computer forensic examiner.