This course provides the fundamental knowledge and skills required to preview and acquire images from Windows-based and macOS-based computers, mobile devices, and removable storage media in a forensically sound manner.
Presentations and hands-on practical exercises cover the following topics:
- Storage media and how data is stored;
- Firmware interfaces (BIOS, UEFI);
- The previewing process;
- Live and dead-box previewing;
- The forensic acquisition process;
- Tool validation;
- Hardware and software write blockers;
- Forensic image formats; and
- Multiple forensic acquisition methods.
Students will use free and commercial third-party tools that are currently used by practitioners in the field.