With this course participants will understand the introduction to forensic analysis using the necessary tools and techniques on Windows Systems.
Who Should Participate?
Information Security Specialists, System Specialists, Network Specialists, Forensic Informatics Specialists, Law Enforcement, Cyber Incident Response Specialists
Program
Fundamentals of Forensics/Incident Response Processes
• Forensic Informatics / Incident Response Definitions
• Digital Crime Investigation Processes
• Known Incident Response Processes
File System Basics
File System Analysis
Concepts to be Known in Forensic Analysis Processes
• Hiding/Detecting Data on ADS
• File Signatures
• Data Volatility Rankings
Detection and Analysis of Traces of Applications Running on Windows Systems
Windows Registry Analysis
Analysis of Windows Event Log Records
Memory Analysis
• Memory Image Acquisition
• Analyzing the Memory Image
• Malware Detection with Memory Analysis
Fundamentals of Threat Hunting and Detection Techniques
Windows System Processes
Web Browser Analysis
Tools and Usage Methods that can be used in Forensic Analysis Stages
Sample Attack Scenarios and Applied Forensic Analysis/Incident Intervention Procedures to be Performed on These Scenarios