![]() |
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Unpatched, unprotected computers connected to the internet are compromised in less than three days. Government regulations and organizational policy might require computer forensic investigators to investigate intellectual property theft, harassment, and regulatory compliance. Investigators must master a variety of operating systems, investigation techniques, incident response tactics, and even legal issues in order to solve their cases. This course will teach you forensic techniques and tools in a hands-on setting for both Windows- and Linux-based investigations. This course emphasizes a hands-on approach where you will learn in-depth forensic functionality and how to solve a variety of incidents. Most incident response and security personnel will need to be familiar with core forensic techniques in order to respond to a variety of incidents for their organizations. This course teaches investigators how to follow the trail typical for intrusions and incidents that they might encounter. Incident responders should learn how intruders breached the infrastructure to identify additional systems/networks that are compromised. You will learn how to investigate traces left by complex attacks using the latest exploit methodologies. Learning more than just how to use a forensic tool, you will be able to demonstrate how the tool functions step-by-step. You will become skilled with tools, such as the Sleuthkit, Foremost, and the HELIX Forensics Live CD. We will rapidly move on to advanced forensic and investigation analysis topics and techniques. This SANS hands-on technical course arms you with a deep understanding of the forensic methodology, tools, and techniques to solve even the most difficult case. FIGHT CRIME. UNRAVEL INCIDENTS... ONE BYTE AT A TIME. We not only teach a firm understanding of the computer forensics tools and techniques, we also teach you the legally approved forensic methodology that will result in success. As part of the course, you will receive the SANS Investigative Forensic Toolkit (SIFT). Using the hardware and software in this toolkit, you will gain first-hand experience in collecting and analyzing evidence recovered from a system under investigation. You will learn best practices on how to investigate and recover deleted data. The course will demonstrate how forensic tools recover evidence so you can articulate how the tool works in depth. We will examine various investigation methodologies and techniques discovering new places to find evidence and discover the tracks of a motivated suspect who is trying to stay hidden. The SIFT Toolkit consists of: -Hard Drive USB evidence acquisition kit for SATA/IDE hard drives 1.8"/2.5"/3.5"/5.25" -HELIX incident response & computer forensics live CD -SANS VMware-based forensic analysis workstation equipped to investigate forensic data -Course DVD loaded with case examples, tools, and documentation -Best-selling book File System Forensic Analysis by Brian Carrier Code: http://rapidshare.com/files/204873584/508.part11.rar http://rapidshare.com/files/204865389/508.part07.rar http://rapidshare.com/files/204856411/508.part30.rar http://rapidshare.com/files/203888188/508.part29.rar http://rapidshare.com/files/203883309/508.part28.rar http://rapidshare.com/files/203879145/508.part27.rar http://rapidshare.com/files/203874832/508.part26.rar http://rapidshare.com/files/203870794/508.part25.rar http://rapidshare.com/files/203866274/508.part24.rar http://rapidshare.com/files/203861486/508.part23.rar http://rapidshare.com/files/203856417/508.part22.rar http://rapidshare.com/files/203851067/508.part21.rar http://rapidshare.com/files/203845983/508.part20.rar http://rapidshare.com/files/203840703/508.part19.rar http://rapidshare.com/files/203834668/508.part18.rar http://rapidshare.com/files/203828935/508.part17.rar http://rapidshare.com/files/203823129/508.part16.rar http://rapidshare.com/files/203816878/508.part15.rar http://rapidshare.com/files/203810619/508.part14.rar http://rapidshare.com/files/203804140/508.part13.rar http://rapidshare.com/files/203795460/508.part12.rar http://rapidshare.com/files/203779434/508.part10.rar http://rapidshare.com/files/203770023/508.part09.rar http://rapidshare.com/files/203760839/508.part08.rar http://rapidshare.com/files/203743781/508.part06.rar http://rapidshare.com/files/203735220/508.part05.rar http://rapidshare.com/files/203726412/508.part04.rar http://rapidshare.com/files/203717177/508.part03.rar http://rapidshare.com/files/203707604/508.part02.rar http://rapidshare.com/files/203698581/508.part01.rar http://rapidshare.com/files/203689943/508.part31.rar |
![]() |
| Thread Tools | |
| Display Modes | |
| |