Learn the fundamentals of operating system forensics. Find out how to recover evidence from the operating system of any computer.
Overview
Syllabus
Introduction
- Operating system forensics
- Introduction
- History
- Core concepts
- Roles in computing
- Process management hands-on
- Roles in forensics
- Future
- Introduction
- Windows file systems
- Windows hands-on
- Linux file systems
- Linux hands-on
- Apple file systems
- Apple hands-on
- Introduction
- Data carving
- Data carving preparation
- Data carving hands-on
- Slack space
- Data hiding and ADS
- Data hiding hands-on
- Introduction
- Addressing
- Memory structure
- Virtual memory
- Memory dump analysis with Volatility
- Processes
- Network connections
- Challenge
- Solution
- Next steps
Taught by
Jungwoo Ryoo