Operating System Forensics

Go to class
Write Review

Free Online Course: Operating System Forensics provided by LinkedIn Learning is a comprehensive online course, which lasts for 1-2 hours worth of material. The course is taught in English and is free of charge. Upon completion of the course, you can receive an e-certificate from LinkedIn Learning. Operating System Forensics is taught by Jungwoo Ryoo.

Overview
  • Learn the fundamentals of operating system forensics. Find out how to recover evidence from the operating system of any computer.

Syllabus
  • Introduction

    • Operating system forensics
    1. Operating Systems and Digital Forensics
    • Introduction
    • History
    • Core concepts
    • Roles in computing
    • Process management hands-on
    • Roles in forensics
    • Future
    2. File System Types
    • Introduction
    • Windows file systems
    • Windows hands-on
    • Linux file systems
    • Linux hands-on
    • Apple file systems
    • Apple hands-on
    3. File Recovery
    • Introduction
    • Data carving
    • Data carving preparation
    • Data carving hands-on
    • Slack space
    • Data hiding and ADS
    • Data hiding hands-on
    4. Live Acquisition
    • Introduction
    • Addressing
    • Memory structure
    • Virtual memory
    • Memory dump analysis with Volatility
    • Processes
    • Network connections
    Conclusion
    • Next steps