Prerequisites
- Before any forensic acquisition you must document the evidence
- See my Cybrary course: “Evidence Handling: Do it the Right Way”
- See my Cybrary course: “Basic Evimetry Deadboot Forensic Acquisition: Wired & Local”
- Internet connected computer
- An evaluation copy of Evimetry
- An “evidence” computer or drive
- A USB thumb drive for booting
- A Wi-Fi Network
- A DHCP source
- A storage drive (USB3 External)
Course Goals
By the end of this course, students should be able to:
- How to edit the Evimetry Deadboot Dongle for Wi-Fi
- Use Wi-Fi Dongles that work
- How to use the Evimetry Deadboot USB dongle and Evimetry Controller to manage a forensic acquisition across a Wi-Fi network.