This course provides the fundamental knowledge and skills required to acquire forensic backup images of commonly encountered forms of digital evidence (Microsoft Windows-based computers and external storage devices) in a forensically sound manner.
Presentations and hands-on practical exercises cover the following topics:
- Storage media and how data is stored
- The forensic acquisition process
- Tool validation
- Hardware and software write blockers
- Forensic backup image formats
- Multiple forensic acquisition methods
Students will use free and commercial third-party tools that are currently used by practitioners in the field.