This course will provide an in-depth look at The Sleuth Kit and Foremost. These two complementary software packages are a reliable set of tools useful for analyzing forensic evidence from multiple file systems, including Windows- (NTFS and FAT) and Linux-based (EXT2 and EXT3) file systems.
As a forensic investigator, it is important to understand multiple ways to find and recover data from collected evidence. You will learn how to perform string searches looking for an e-mail address or bytes found at the beginning of a zip file in order to recover the pertinent data from your evidence and determine the filename that contains that data. Additionally, you will learn how to accomplish data recovery using the data layer and the meta-data layer of the file system.
Performing hash database comparisons and file type sorting is also a very powerful way to help narrow the focus of an investigator. You will learn how to create a forensic hash database and use it to identify known and potentially malicious data in your evidence.
Finally, you will learn how an automated toolkit works to help you speed up the process of an investigation using the Autopsy Forensic Browser and discuss how similar commercial tools perform the same functionality.
The techniques covered in the course today utilize similar techniques that will successfully analyze Windows NTFS/FAT file systems as well as Unix-based file system variations, such as Ext2/3, UFS, and FFS.
| SECURITY 508 Upcoming Events | |||
| Event | Location | Dates | Delivery Method |
| SANS SelfStudy | Books & MP3s Only | Anytime | Self Paced |
| SANS OnDemand | Online | Anytime | Self Paced |
| SANS London 2009 | London, United Kingdom | Nov 28, 2009 - Dec 06, 2009 | Live Event |
| Community SANS Tucson 2009 | Tucson, AZ | Nov 30, 2009 - Dec 05, 2009 | Community SANS |
| Community SANS Colorado Springs 2009 | Colorado Springs, CO | Nov 30, 2009 - Dec 05, 2009 | Community SANS |
| Mentor Session - SEC508 | Atlanta, GA | Dec 02, 2009 - Feb 17, 2010 | Mentor |
| Mentor Session - SEC508 | Medellín, Colombia | Dec 02, 2009 - Dec 04, 2009 | Mentor |
| SANS CDI East 2009 | Washington DC | Dec 11, 2009 - Dec 18, 2009 | Live Event |
| Mentor Session - Security 508 | Charlotte, NC | Jan 14, 2010 - Mar 18, 2010 | Mentor |
| Mentor Session - Security 508 | Denver, CO | Jan 19, 2010 - Mar 23, 2010 | Mentor |
| Community SANS Lake Tahoe 2010 | Lake Tahoe, CA | Jan 25, 2010 - Jan 30, 2010 | Community SANS |
| SANS Phoenix 2010 | Phoenix, AZ | Feb 14, 2010 - Feb 20, 2010 | Live Event |
| SANS India 2010 | Bangalore, India | Feb 22, 2010 - Feb 27, 2010 | Live Event |
| SANS 2010 | Orlando, FL | Mar 06, 2010 - Mar 15, 2010 | Live Event |
| Mentor Session - SEC508 | Greeley, CO | Mar 11, 2010 - May 13, 2010 | Mentor |
| Community SANS Boston 2010 | Boston, MA | Mar 15, 2010 - Mar 20, 2010 | Community SANS |
| SANS vLive! - SEC 508 - Rob Lee | SANS vLive! SEC508 - 201003, VA | Mar 23, 2010 - Apr 29, 2010 | |
| SANS Northern Virginia Bootcamp 2010 | Reston, VA | Apr 06, 2010 - Apr 13, 2010 | Live Event |
| Mentor Session - SEC508 | Boise, ID | Sep 28, 2010 - Nov 30, 2010 | Mentor |