Learning Tree International

Tel: 08-506 668 00
 

Önskar du mer information?

Förnamn*:

Efternamn*:

Funktion:

Internadress:

Företag*:

Adress*:

Ort*:

Postnummer*:

Land* :
   Landskoder

Telefonnummer*:

E-post*:

* = Obligatoriskt

Informationen du lämnar kommer att användas för att kommunicera med dig om Learning Tree-produkter som kan vara av intresse för dig. Sekretessregler

När vi tagit emot ditt formulär tar vi kontakt med dig via e-post eller telefon.

Tidsbegränsat erbjudande  – Spara upp till 40 % per kurs
 

Implementing an Incident Response Strategy: Hands-On

Conducting Forensics on Windows®-Based Systems


Kurs: 5364 dagar

 Tipsa kollega   Skriv ut   Frågor och svar   Ladda ner PDF   Facebook   Twitter    View in English

Boka direkt

Denna kurs är schemalagd i England och USA, du kan välja mellan att resa dit eller delta live, online via AnyWare. Kursen går även att hålla företagsinternt på plats hos er. Ring 08-506 668 00 eller skicka oss en förfrågan genom att klicka här.

You Will Learn How To

  • Implement a computer forensics incident-response strategy
  • Lead a successful investigation from the initial response to completion
  • Conduct disc-based analysis and recover deleted files
  • Identify information-hiding techniques
  • Reconstruct user activity from e-mail, temporary Internet files and cached data
  • Assess the integrity of system memory and process architecture to reveal malicious codes

Course Benefits

Do you know what to do if your organisation's security is compromised? Threats of computer crime against an organisation's infrastructure have grown substantially, but there are steps you can take. In this course, you apply the latest Windows-based computer forensic techniques to uncover illicit activity and recover lost data. Every crime leaves behind clues. With the right tools, you can effectively respond to and counteract security threats.

Who Should Attend

Systems administrators and those involved in responding to security incidents. Knowledge of Windows-based PCs, including hardware and operating system software, at the level of Course 2400, "Windows 7 Comprehensive Introduction", is assumed

Hands-On Training

Exercises, providing experience using software forensic tools to investigate Windows-based systems, include:
  • Leveraging case-management software
  • Employing forensic toolkits
  • Imaging digital media
  • Hiding and discovering potential evidence
  • Applying steganography techniques
  • Manipulating alternate data streams
  • Discovering information in mangled files
  • Conducting e-mail investigations
  • Reconstructing browser and Web server activity
  • Establishing covert surveillance with keystroke loggers and remote access
  • Configuring tools to detect a rootkit

Course Content

Introduction to Computer Forensics

  • Responding to incidents
  • Applying forensic analysis skills
  • Distinguishing between unpermitted corporate and criminal activity

Handling Preliminary Investigations

Planning for incident response

  • Knowing your organisation's policies
  • Minimising impact on your organisation

Identifying the incident life cycle

  • Performing incident analysis
  • Capturing volatile information

Controlling an Investigation

Collecting digital evidence

  • Chain of custody and process integrity
  • Advantages of the forensics analysis team

Legal aspects of acquiring evidence

  • Securing and documenting the scene
  • Processing and logging evidence

Conducting Disk-Based Analysis

Forensics lab operations

  • Acquiring a bit-stream image
  • Enabling a write blocker
  • Establishing a baseline
  • Physically protecting the media

Disk structure and recovery techniques

  • Disk geometry components
  • Inspecting Windows file system architectures
  • Locating and restoring deleted content

Investigating Information-Hiding Techniques

Uncovering potential cybersecurity threats or leaks

  • Scanning and evaluating alternate data streams
  • Executing code from a stream
  • Steganography tools and concepts
  • Detecting steganography
  • Scavenging slack space

Inspecting header signatures and file mangling

  • Combining files
  • Binding multiple executable files
  • File time analysis

Scrutinising E-mail

Investigating the mail client

  • Interpreting e-mail headers
  • Recovering deleted e-mails

Validating e-mail header information

  • Detecting spoofed e-mail
  • Verifying e-mail routing

Tracing Internet Access

Inspecting browser cache and history files

  • Exploring temporary Internet files
  • Researching cookie storage
  • Reconstructing cleared browser history
  • Assessing antiforensics features browsers
  • Updated browser analysis

Auditing Internet surfing

  • Tracking user activity
  • Uncovering unauthorised usage

Searching Memory in Real Time

Comparing the architecture of processes

  • Identifying user and kernel memory
  • Inspecting threads
  • Discovering rogue DLLs and drivers

Employing advanced process analysis methods

  • Evaluating processes with Windows Management Instrumentation (WMI)
  • Walking dependency trees

Auditing processes and services

  • Investigating the process table
  • Discovering evidence in the Registry
  • Deploying and detecting a rootkit

Implementing covert surveillance techniques

  • Logging key strokes
  • Observing real-time remote desktops
  • Monitoring Internet access

<< Tillbaka till Säkerhet
 

Liknande kurser


Windows Server is a registered trademark of Microsoft Corporation.
 
Implementing an Incident Response Strategy

Kursschema

Learning Tree AnyWare Du kan gå de överstrukna kurserna i klassrummet eller live, online via Learning Tree AnyWareTM.

Storbritannien

10 - 13 juliLondon boka kurs

USA

21 - 24 febWashington boka kurs
29 maj - 1 juniWashington boka kurs
19 - 22 juniWashington boka kurs
17 - 20 juliNew York boka kurs

När du ska gå en AnyWare-kurs bör du anmäla dig minst 10 dagar före kursstart.

Fler datum och platser.

Kurspriser

22 950 krOrd. Pris
kurspriser med
rabattprogram
14 300 krMed Treklöver
12 975 krMed Fyrklöver
17 350 krMed Företagskort -
10-kort
17 360 krMed ProPack 40
Alla priser i SEK, exkl moms.

Företagsintern &
anpassad utbildning

Denna och alla andra Learning Tree-kurser kan ges på plats hos er och/eller anpassas för er organisation.

Implementing an Incident Response Strategy: Hands-On

Course participants conducting a disk-based forensic investigation.


Kursdeltagarnas genomsnittsbedömning

De senaste 12 månadernas bedömningar

5 stjärnor:
71 %
4 stjärnor:
21 %
3 stjärnor:
7 %
2 stjärnor:   0 %
1 stjärna:
1 %

 
"As a remote course attendee, the Learning Tree AnyWare format was excellent for this type of learning. It should be the industry standard".



 
Ten Questions to Ask Your Training Provider - Position Paper