Get in Touch

Course Outline

Introduction to Kali Linux for Forensics

  • Overview of Kali Linux and its forensic functionalities
  • Setting up a laptop optimized for forensic use
  • Maintaining the chain of custody and addressing legal implications

Disk and File System Forensics

  • Processes for disk acquisition and imaging
  • File system examination utilizing Autopsy and Sleuth Kit
  • Techniques for recovering deleted files and uncovering hidden data

Memory and Process Analysis

  • Capturing volatile memory states
  • Investigating active processes and malware behaviors
  • Applying Volatility for detailed memory analysis

Network Forensics

  • Methodologies for capturing live network traffic
  • Packet inspection and analysis with Wireshark and tcpdump
  • Tracking intrusion patterns and lateral movement activities

Log and Artifact Analysis

  • Thorough review of system and application logs
  • Identification of indicators and artifacts of compromise
  • Constructing chronological timelines of incident events

Incident Investigation Workflow

  • Evidence acquisition procedures and integrity validation
  • Implementing a structured investigation methodology
  • Documenting findings for effective stakeholder communication

Advanced Tools and Techniques

  • Exploring mobile device forensic utilities within Kali
  • Analyzing steganography and encryption mechanisms
  • Scripting for the automation of repetitive forensic tasks

Summary and Next Steps

Requirements

  • Fundamental knowledge of the Linux command line
  • A solid grasp of core cybersecurity principles
  • Practical experience in incident response or IT security operations

Intended Audience

  • Digital forensic investigators
  • Members of incident response teams
  • IT security specialists
 21 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories