Description
The challenge of computer forensics is to find the data, collect it and present it in a court of law. This intensive course allows participants to develop the expertise necessary to meet this challenge and also to take the official certification exam, accredited by PECB.
Who is this training for ?
For whom ?Computer investigation specialist, data analyst, specialist in research and recovery of computer evidence, security team member, consultant, electronic media analyst.
Prerequisites
Training objectives
Training program
- Scientific principles specific to computer investigation
- Presentation of the scientific principles specific to computer investigation.
- Introduction to the computer investigation approach.
- Fundamental principles.
- Analysis and implementation of analysis operations.
- Preparation and execution of investigation procedures.
- Structure of computers and operating systems
- Identification and selection of computer components.
- Identification and selection of peripherals and other components.
- Understanding operating systems (OS).
- Extracting and analyzing file structures.
- Network, Cloud and mobile device investigation
- Understanding networks, cloud and virtual environments.
- Generic methods for extracting data in a virtual environment.
- Review of a mobile phone or tablet.
- Storing information on mobile devices.
- Investigation tools and methodologies
- Enumeration and examination of computer hardware and software components.
- Selection and testing of investigation technologies.
- Analysis and selection of suitable procedures for investigation operations 'investigation.
- Discovery, documentation and return of evidence on site.
- Analysis and consideration of the context.
- Investigation tools and methodologies
- Enumeration and examination of computer hardware and software components.
- Selection and testing of investigation technologies.
- Analysis and selection of suitable procedures for investigation operations 'investigation.
- Discovery, documentation and return of evidence on site.
- Analysis and consideration of the context.
- Certification exam
- Domain 1: scientific principles specific to computer investigation.
- Domain 2: fundamental principles of computer investigation.
- Domain 3: structure of computers.
- Domain 4: operating systems and file structures.
- Domain 5: investigation of networks, in the Cloud or in virtual environments.
- Domain 6: network and mobile device investigation.
- Domain 7: investigative tools and methodologies.
- Domain 8: examination, acquisition and preservation of electronic evidence.
- Exam 3 hour exam.