Data Storage Foundations – Certification Course (Live On-Site, Manchester, UK) – Feb 2024
4-day Certification Intermediate Course
Course Overview
This Four-day course is designed for the examiner tasked with the recovery and analysis of data collected from electronic evidence. Early modules examine techniques in the recovery of volatile data (RAM) including basic analysis techniques and a review of file system fundamentals. This will be followed by an in-depth analysis of the architecture and functionality of the Microsoft New Technology File System (NTFS), and the exFAT file systems, including the detailed examination of related directory entry information for locating files on electronic media. Attendees will gain insights into the effects of the formatting process and how the system areas function as well as file data management and directory entry metadata pertaining to the stored data. All forensically relevant areas will be examined in detail as well as techniques for identifying potential evidence that may be pivotal to a successful advanced examination. These topics will be followed by a more in-depth analysis of forensic artifacts within a modern Windows environment that includes advanced Windows Registry examination, introduction to SQLite databases, and recovery of deleted files for the examination of artifacts aligned to user activity.
Students will apply this new knowledge to artifacts located on Windows-based systems where there will be a direct correlation between the File System and Operating System Application functions such as Distributed Link Tracking services, Windows 10 Timeline function, and other Operating System-related artifacts.
Students will use a variety of open-source and leading forensic applications to examine key artifacts through multiple hands-on labs and student exercises.
What you will receive:
Printed course manual · Student USB · Access to the Spyder Forensics Academy · Course certificate